Local and Central Differential Privacy for Robustness and Privacy in Federated Learning
Mohammad Naseri, Jamie Hayes, Emiliano De Cristofaro
Abstract
Federated Learning (FL) allows multiple participants to train machine learning models collaboratively by keeping their datasets local while only exchanging model updates. Alas, this is not necessarily free from privacy and robustness vulnerabilities, e.g., via membership, property, and backdoor attacks. This paper investigates whether and to what extent one can use differential Privacy (DP) to protect both privacy and robustness in FL. To this end, we present a first-of-its-kind evaluation of Local and Central Differential Privacy (LDP/CDP) techniques in FL, assessing their feasibility and effectiveness. Our experiments show that both DP variants do d fend against backdoor attacks, albeit with varying levels of protection-utility trade-offs, but anyway more effectively than other robustness defenses. DP also mitigates white-box membership inference attacks in FL, and our work is the first to show it empirically. Neither LDP nor CDP, however, defend against property inference. Overall, our work provides a comprehensive, re-usable measurement methodology to quantify the trade-offs between robustness/privacy and utility in differentially private FL.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 51d4ae26-6060-4e14-ad9e-fcf272760338Cited by top-tier papers31
- EIFFeL: Ensuring Integrity for Federated LearningAmrita Roy Chowdhury, Chuan Guo, Somesh Jha, Laurens van der MaatenCCS 2022 · 70 citations
- RFLPA: A Robust Federated Learning Framework against Poisoning Attacks with Secure AggregationPeihua Mai, Ran Yan, Yan PangNeurIPS 2024 · 51 citations
- Chameleon: Adapting to Peer Images for Planting Durable Backdoors in Federated LearningYanbo Dai, Songze LiICML 2023 · 45 citations
- LeadFL: Client Self-Defense against Model Poisoning in Federated LearningChaoyi Zhu, Stefanie Roos, Lydia Y. ChenICML 2023 · 33 citations
- BackdoorIndicator: Leveraging OOD Data for Proactive Backdoor Detection in Federated LearningSongze Li, Yanbo DaiUSENIX Security 2024 · 31 citations
Builds on28
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- Stealing Machine Learning Models via Prediction APIsFlorian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter et al.USENIX Security 2016 · 2,088 citations
Related papers
- Towards the Robustness of Differentially Private Federated LearningTao Qi, Huili Wang, Yongfeng HuangAAAI 2024 · 30 citations
- Unraveling the Connections between Privacy and Certified Robustness in Federated Learning Against Poisoning AttacksChulin Xie, Yunhui Long, Pin-Yu Chen, Qinbin Li et al.CCS 2023 · 12 citations
- Theoretically Unmasking Inference Attacks Against LDP-Protected Clients in Federated Vision ModelsQuan Minh Nguyen, Minh N. Vu, Truc Nguyen, My T. ThaiICML 2025
- Lightweight Federated Learning with Differential Privacy and Straggler ResilienceShu Hong, Xiaojun Lin, Lingjie DuanINFOCOM 2025 · 7 citations
- Interaction-level Membership Inference Attack Against Federated Recommender SystemsWei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui et al.WWW 2023 · 101 citations
