Gradients Leak Text in Split Learning: 97.38% Token, 37.77% Document Recovery

Setloop · hf · 2026-10-06

A Hugging Face paper quantifies text leakage in split learning, where a client runs early LM layers locally and sends activations to a server.

Key findings

The authors recommend reporting leakage per token and per document, and treating split-model traffic as sensitive as raw text.

Original post →

More from Safety

Safety channel →