Verifiable Gradient Inversion Attack Proves Reconstruction Correctness in Federated Learning Without Visual Inspection
arXiv·medium signal
A new gradient inversion attack against federated learning can certify whether its reconstructions are correct — solving a fundamental problem where existing attacks produce outputs with no intrinsic way to verify success. Unlike vision and language domains where human inspection can judge plausibility, numerical tabular records cannot be visually verified, making certified reconstruction a critical capability for assessing federated learning privacy risks.