Engineering Papers⌕ Search

DOE OSTI · 3009440

Position-Enhanced Gradient Attack (PEGA) on Medical Language Models

Abstract

Federated Learning (FL) enables collaborative training of language models on sensitive clinical notes without sharing the data. However, this paradigm is vulnerable to gradient inversion attacks that can reconstruct private data from shared gradients. We find that state-of-the-art attacks are less effective in the medical domain, failing to overcome the unique challenges posed by its specialized vocabulary and unstructured format. To address this, we introduce the Position-Enhanced Gradient Attack (PEGA), a novel attack that makes gradients position-aware by optimizing token and position embeddings simultaneously. PEGA employs two key innovations: a periodic sorting of positional embeddings to resolve token order ambiguity and a late-stage embedding replacement strategy to correct hard-to-recover critical tokens. To evaluate the leakage of sensitive data more directly, we also propose the Unified PHI-Recall (UPHI), a new metric measuring the recovery of Protected Health Information. Experiments on the MIMIC-III dataset show that PEGA significantly outperforms leading attacks like TAG and LAMP, particularly in its ability to reconstruct identifiable patient information, exposing a more severe and nuanced privacy risk in federated medical NLP.

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Xu, Nuo [University of Minnesota], Stanley, Christopher [ORNL] (ORCID:0000000242267710), Gounley, John [ORNL] (ORCID:0000000184244982), Hanson, Heidi [ORNL] (ORCID:000000030056196X), Ge, Chang [University of Minnesota] (ORCID:0000000187884379), Ding, Caiwen [University of Minnesota]. 2025-12-01. Position-Enhanced Gradient Attack (PEGA) on Medical Language Models. https://doi.org/10.1145/3743093.3771065

Cite the original work for its findings. Save a collection to share your selection of sources.