ARTFEED — Contemporary Art Intelligence

Gradient Inversion Attack on LoRA Fine-Tuning in Federated Learning

ai-technology · 2026-08-04

A recent study published on arXiv (2608.01521) introduces an analytical gradient inversion attack aimed at low-rank adaptation (LoRA) fine-tuning within federated learning environments. This attack allows a malicious server to extract confidential user information by incorporating fine-tuning data into the shared gradients. The authors emphasize the insufficiently examined resilience of federated fine-tuning against adversarial servers, which can manipulate the training process to compromise user privacy. By utilizing a contaminated pretrained model and fine-tuning parameters, the method reconstructs private data. This research highlights an escalating issue as PEFT techniques like LoRA gain traction in federated learning to minimize communication and computational demands, stressing the urgent need for enhanced privacy protections in distributed learning frameworks.

Key facts

  • Paper arXiv:2608.01521 proposes an analytical gradient inversion attack on LoRA fine-tuning.
  • The attack allows a malicious server to recover private user data.
  • It leverages a poisoned pretrained model and fine-tuning parameters.
  • The method embeds fine-tuning data within shared gradients.
  • Federated learning with LoRA reduces communication and computation costs.
  • Users download a pretrained model and fine-tune LoRA modules locally.
  • Only gradients of fine-tuning parameters are shared with the server.
  • Robustness of federated fine-tuning against adversarial servers is underexplored.

Entities

Institutions

  • arXiv

Sources