{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/user-label-leakage-from-gradients-in","title":"User-Level Label Leakage from Gradients in Federated Learning","arxiv_id":"2105.09369","date":"2021-05-19","proceeding":null,"authors":["Aidmar Wainakh","Fabrizio Ventola","Till Müßig","Jens Keim","Carlos Garcia Cordero","Ephraim Zimmer","Tim Grube","Kristian Kersting","Max Mühlhäuser"],"abstract":"Federated learning enables multiple users to build a joint model by sharing their model updates (gradients), while their raw data remains local on their devices. In contrast to the common belief that this provides privacy benefits, we here add to the very recent results on privacy risks when sharing gradients. Specifically, we investigate Label Leakage from Gradients (LLG), a novel attack to extract the labels of the users' training data from their shared gradients. The attack exploits the direction and magnitude of gradients to determine the presence or absence of any label. LLG is simple yet effective, capable of leaking potential sensitive information represented by labels, and scales well to arbitrary batch sizes and multiple classes. We mathematically and empirically demonstrate the validity of the attack under different settings. Moreover, empirical results show that LLG successfully extracts labels with high accuracy at the early stages of model training. We also discuss different defense mechanisms against such leakage. Our findings suggest that gradient compression is a practical technique to mitigate the attack.","url_abs":"https://arxiv.org/abs/2105.09369v4","url_pdf":"https://arxiv.org/pdf/2105.09369v4.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"user-label-leakage-from-gradients-in","repo_url":"https://github.com/tklab-tud/llg","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}},{"paper_slug":"user-label-leakage-from-gradients-in","repo_url":"https://github.com/JonasGeiping/breaching","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"federated-learning","task_name":"Federated Learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2105.09369","atlas_url":"https://app.syntology.ai/?focus=2105.09369","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2105.09369"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/tklab-tud/llg","reach":{"status":"ok","spdx":"MIT"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/JonasGeiping/breaching","reach":null}],"summary":{"unverified":6},"by_repo_kind":{"official":{"samples":6,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"9c8e06f51ff7cdca","entry":"append_runs","repo":"tklab-tud/llg","repo_kind":"official","path":"Code/visualize_experiment.py","file_url":"https://github.com/tklab-tud/llg/blob/HEAD/Code/visualize_experiment.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"9c8e06f51ff7cdca"}},{"code_sha256_prefix":"0b79095a08401ccd","entry":"conv_bn","repo":"tklab-tud/llg","repo_kind":"official","path":"Code/model.py","file_url":"https://github.com/tklab-tud/llg/blob/HEAD/Code/model.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"0b79095a08401ccd"}},{"code_sha256_prefix":"194788f555f737e2","entry":"get_meta","repo":"tklab-tud/llg","repo_kind":"official","path":"Code/visualize_experiment.py","file_url":"https://github.com/tklab-tud/llg/blob/HEAD/Code/visualize_experiment.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"194788f555f737e2"}},{"code_sha256_prefix":"a40830b557a11160","entry":"resnet18","repo":"tklab-tud/llg","repo_kind":"official","path":"Code/model.py","file_url":"https://github.com/tklab-tud/llg/blob/HEAD/Code/model.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"a40830b557a11160"}},{"code_sha256_prefix":"aec3de1f6493541c","entry":"resnet20","repo":"tklab-tud/llg","repo_kind":"official","path":"Code/model.py","file_url":"https://github.com/tklab-tud/llg/blob/HEAD/Code/model.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"aec3de1f6493541c"}},{"code_sha256_prefix":"ac9a418ce3a64ae3","entry":"visualize_flawles_class_prediction_accuracy_vs_batchsize","repo":"tklab-tud/llg","repo_kind":"official","path":"Code/visualize_experiment.py","file_url":"https://github.com/tklab-tud/llg/blob/HEAD/Code/visualize_experiment.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"ac9a418ce3a64ae3"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}