What Gradients Add to Text Leakage in Split Language Models, Counted per Token and per Document
Split learning lets a client train a language model on a server without sending its text. The client runs the first layers itself and sends the server only their output, a vector of numbers for each token. During training, the server sends gradients back. We show that an observer at the split can rebuild most of the cl...