{
  "$schema": "https://themachinepress.com/schemas/story-v1.schema.json",
  "schema_version": "1.0.0",
  "document_type": "machine_press_story",
  "story": {
    "story_id": "mp-2026-08-22-008",
    "source_story_id": "tmp-story-aegis-gradient-leakage",
    "edition_id": "mp-2026-08-22-morning-0044",
    "edition_url": "https://themachinepress.com/edition/2026-08-22",
    "position": 8,
    "story_type": "dispatch",
    "section": "safety-security",
    "editorial_classification": "editorial",
    "headline": "Three Gradient Channels Gave the Tokens Away",
    "slug": "three-gradient-channels-gave-the-tokens-away",
    "dek": "AEGIS masked attention, embedding and MLP leakage paths in federated language-model fine-tuning.",
    "summary": "AEGIS masked attention, embedding and MLP leakage paths in federated language-model fine-tuning.",
    "body_text": "The paper identifies three structural signals that gradient-inversion attacks can use to recover private training text: attention-projection subspaces, sparse embedding rows and an MLP expansion signal. AEGIS freezes or perturbs those backward paths and uses the same masked gradient locally and at the server boundary. Across 11 models and six datasets, the authors report near-zero token recovery with utility preserved or improved; deployment claims still depend on the tested attacks and threat model.",
    "why_it_matters": "AEGIS masked attention, embedding and MLP leakage paths in federated language-model fine-tuning.",
    "limitations": [],
    "importance": 9,
    "canonical_url": "https://themachinepress.com/story/mp-2026-08-22-008/three-gradient-channels-gave-the-tokens-away",
    "json_url": "https://themachinepress.com/story/mp-2026-08-22-008.json",
    "first_published_at": "2026-08-22T09:00:00.000-04:00",
    "modified_at": "2026-08-22T09:00:00.000-04:00",
    "content_status": "new",
    "is_carryover": false,
    "carryover_reason": null,
    "key_claims": [
      {
        "claim_id": "claim-mp-2026-08-22-008-001",
        "text": "AEGIS masked attention, embedding and MLP leakage paths in federated language-model fine-tuning.",
        "source_ids": [
          "source-2026-08-22-008"
        ],
        "qualification": null
      }
    ],
    "source_ids": [
      "source-2026-08-22-008"
    ],
    "tags": [
      "federated learning",
      "privacy",
      "gradient inversion",
      "language models"
    ],
    "image_url": "https://themachinepress.com/issues/2026-08-22/aegis-security-file-image.webp",
    "corrections": []
  },
  "sources": [
    {
      "source_id": "source-2026-08-22-008",
      "title": "arXiv preprint 2608.19534",
      "publisher": "arXiv",
      "url": "https://arxiv.org/abs/2608.19534",
      "canonical_url": "https://arxiv.org/abs/2608.19534",
      "source_type": "primary_research",
      "is_primary_source": true,
      "published_at": "2026-08-19T20:00:00.000-04:00",
      "accessed_at": "2026-08-22T08:29:14.000-04:00",
      "supports_claim_ids": [
        "claim-mp-2026-08-22-008-001"
      ]
    }
  ],
  "corrections": [],
  "publisher": {
    "name": "The Machine Press",
    "url": "https://themachinepress.com",
    "description": "A daily newspaper for the age of artificial intelligence."
  },
  "cite_this_report": {
    "title": "Three Gradient Channels Gave the Tokens Away",
    "publisher": "The Machine Press",
    "published_at": "2026-08-22T09:00:00.000-04:00",
    "canonical_url": "https://themachinepress.com/story/mp-2026-08-22-008/three-gradient-channels-gave-the-tokens-away"
  }
}
