DRAUN: An Optimization-Agnostic Data Reconstruction Attack on Federated Unlearning

Hithem Lamri, Manaar Alam, Haiyan Jiang, Michail Maniatakos
Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, PMLR 300:4906-4914, 2026.

Abstract

Federated Unlearning (FU) enables clients to remove the influence of specific data from a collaboratively trained shared global model, addressing regulatory requirements such as GDPR and CCPA. However, this unlearning process introduces a new privacy risk: A malicious server may exploit unlearning updates to reconstructthe data requested for removal, a form of Data Reconstruction Attack (DRA). While DRAs for machine unlearning have been studied extensively in centralized Machine Learning-as-a-Service (MLaaS) settings, their applicability to FU remains unclear due to the decentralized, client-driven nature of FU. This work presents DRAUN, the first attack framework to reconstruct unlearned data in FU systems. DRAUN targets optimization-based unlearning methods, which are widely adopted for their efficiency. We theoretically demonstrate why existing DRAs targeting machine unlearning in MLaaS fail in FU and show how DRAUN overcomes these limitations. We validate our approach through extensive experiments on five datasets and five model architectures, evaluating its performance against five popular unlearning methods, effectively demonstrating that state-of-the-art FU methods remain vulnerable to DRAs.

Cite this Paper


BibTeX
@InProceedings{pmlr-v300-lamri26a, title = { DRAUN: An Optimization-Agnostic Data Reconstruction Attack on Federated Unlearning }, author = {Lamri, Hithem and Alam, Manaar and Jiang, Haiyan and Maniatakos, Michail}, booktitle = {Proceedings of The 29th International Conference on Artificial Intelligence and Statistics}, pages = {4906--4914}, year = {2026}, editor = {Khan, Emtiyaz and Li, Yingzhen and Solin, Arno and Ramdas, Aaditya}, volume = {300}, series = {Proceedings of Machine Learning Research}, month = {02--05 May}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v300/main/assets/lamri26a/lamri26a.pdf}, url = {https://proceedings.mlr.press/v300/lamri26a.html}, abstract = { Federated Unlearning (FU) enables clients to remove the influence of specific data from a collaboratively trained shared global model, addressing regulatory requirements such as GDPR and CCPA. However, this unlearning process introduces a new privacy risk: A malicious server may exploit unlearning updates to reconstructthe data requested for removal, a form of Data Reconstruction Attack (DRA). While DRAs for machine unlearning have been studied extensively in centralized Machine Learning-as-a-Service (MLaaS) settings, their applicability to FU remains unclear due to the decentralized, client-driven nature of FU. This work presents DRAUN, the first attack framework to reconstruct unlearned data in FU systems. DRAUN targets optimization-based unlearning methods, which are widely adopted for their efficiency. We theoretically demonstrate why existing DRAs targeting machine unlearning in MLaaS fail in FU and show how DRAUN overcomes these limitations. We validate our approach through extensive experiments on five datasets and five model architectures, evaluating its performance against five popular unlearning methods, effectively demonstrating that state-of-the-art FU methods remain vulnerable to DRAs. } }
Endnote
%0 Conference Paper %T DRAUN: An Optimization-Agnostic Data Reconstruction Attack on Federated Unlearning %A Hithem Lamri %A Manaar Alam %A Haiyan Jiang %A Michail Maniatakos %B Proceedings of The 29th International Conference on Artificial Intelligence and Statistics %C Proceedings of Machine Learning Research %D 2026 %E Emtiyaz Khan %E Yingzhen Li %E Arno Solin %E Aaditya Ramdas %F pmlr-v300-lamri26a %I PMLR %P 4906--4914 %U https://proceedings.mlr.press/v300/lamri26a.html %V 300 %X Federated Unlearning (FU) enables clients to remove the influence of specific data from a collaboratively trained shared global model, addressing regulatory requirements such as GDPR and CCPA. However, this unlearning process introduces a new privacy risk: A malicious server may exploit unlearning updates to reconstructthe data requested for removal, a form of Data Reconstruction Attack (DRA). While DRAs for machine unlearning have been studied extensively in centralized Machine Learning-as-a-Service (MLaaS) settings, their applicability to FU remains unclear due to the decentralized, client-driven nature of FU. This work presents DRAUN, the first attack framework to reconstruct unlearned data in FU systems. DRAUN targets optimization-based unlearning methods, which are widely adopted for their efficiency. We theoretically demonstrate why existing DRAs targeting machine unlearning in MLaaS fail in FU and show how DRAUN overcomes these limitations. We validate our approach through extensive experiments on five datasets and five model architectures, evaluating its performance against five popular unlearning methods, effectively demonstrating that state-of-the-art FU methods remain vulnerable to DRAs.
APA
Lamri, H., Alam, M., Jiang, H. & Maniatakos, M.. (2026). DRAUN: An Optimization-Agnostic Data Reconstruction Attack on Federated Unlearning . Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, in Proceedings of Machine Learning Research 300:4906-4914 Available from https://proceedings.mlr.press/v300/lamri26a.html.

Related Material