As a guest user you are not logged in or recognized by your IP address. You have
access to the Front Matter, Abstracts, Author Index, Subject Index and the full
text of Open Access publications.
Federated Learning (FL) allows institutions to train shared models without exchanging raw data, making it a promising approach for healthcare applications that involve sensitive electronic health records (EHRs). However, despite this distributed design, the gradients exchanged during training can still reveal private information. In this study, we analyze how vulnerable transformer-based language models are to gradient inversion attacks, focusing on the Decepticons method, which can reconstruct original training text from shared gradients. We simulate a cross-silo FL setup with three types of French clinical reports (genetic, anesthesia, and birth records) to evaluate how batch size and sequence length affect reconstruction quality. Our experiments show that a malicious server can recover clinical text with high accuracy: token-level recovery exceeded 95% when training with batch size 1 and remained above 60% for sequences of up to 512 tokens. Reconstructed examples contained identifying elements (names, dates, genetic markers), revealing serious privacy risks for real-world use. These results emphasize that FL alone is insufficient for sensitive clinical text and that privacy-preserving defenses must be integrated before real-world deployment.
This website uses cookies
We use cookies to provide you with the best possible experience. They also allow us to analyze user behavior in order to constantly improve the website for you. Info about the privacy policy of IOS Press.
This website uses cookies
We use cookies to provide you with the best possible experience. They also allow us to analyze user behavior in order to constantly improve the website for you. Info about the privacy policy of IOS Press.