An Accuracy-Lossless Perturbation Method for Defending Privacy Attacks in Federated Learning
Xue Yang, Yan Feng, Weijun Fang, Jun Shao, Xiaohu Tang, Shu-Tao Xia, Rongxing Lu
Abstract
Although federated learning improves privacy of training data by exchanging local gradients or parameters rather than raw data, the adversary still can leverage local gradients and parameters to obtain local training data by launching reconstruction and membership inference attacks. To defend such privacy attacks, many noises perturbation methods (like differential privacy or CountSketch matrix) have been widely designed. However, the strong defence ability and high learning accuracy of these schemes cannot be ensured at the same time, which will impede the wide application of FL in practice (especially for medical or financial institutions that require both high accuracy and strong privacy guarantee). To overcome this issue, in this paper, we propose an efficient model perturbation method for federated learning to defend reconstruction and membership inference attacks launched by curious clients. On the one hand, similar to the differential privacy, our method also selects random numbers as perturbed noises added to the global model parameters, and thus it is very efficient and easy to be integrated in practice. Meanwhile, the random selected noises are positive real numbers and the corresponding value can be arbitrarily large, and thus the strong defence ability can be ensured. On the other hand, unlike differential privacy or other perturbation methods that cannot eliminate the added noises, our method allows the server to recover the true gradients by eliminating the added noises. Therefore, our method does not hinder learning accuracy at all. Extensive experiments demonstrate that for both regression and classification tasks, our method achieves the same accuracy as non-private approaches and outperforms the state-ofthe-art related schemes. Besides, the defence ability of our method is significantly better than the state-of-the-art related defence schemes. Specifically, for the membership inference attack, our method achieves attack success rate (ASR) of around 50%, which is equivalent to blind guessing. However, the ASR of other defence methods is around 60%, which means that clients have a certain advantage to attack successfully compared with blind guessing. For the reconstruction attack, the ASR of our method is around X. Yang, Y. Feng, W. Fang and S. Xia are with
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 61ce0b57-a5d3-4c17-85b2-47a8061be088Cited by top-tier papers3
- BlockDFL: A Blockchain-based Fully Decentralized Peer-to-Peer Federated Learning FrameworkZhen Qin, Xueqiang Yan, Mengchu Zhou, Shuiguang DengWWW 2024 · 39 citations
- Traceable Federated Continual LearningQiang Wang, Bingyan Liu, Yawen LiCVPR 2024 · 16 citations
- United We Defend: Collaborative Membership Inference Defenses in Federated LearningLi Bai, Junxu Liu, Sen Zhang, Xinwei Zhang et al.USENIX Security 2026
Builds on7
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang et al.ICLR 2020 · 2,930 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 1,581 citations
- BatchCrypt: Efficient Homomorphic Encryption for Cross-Silo Federated LearningChengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang et al.USENIX ATC 2020 · 967 citations
Related papers
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation PerspectiveJingwei Sun, Ang Li, Binghui Wang, Huanrui Yang et al.CVPR 2021
- From Risk to Resilience: Towards Assessing and Mitigating the Risk of Data Reconstruction Attacks in Federated LearningXiangrui Xu, Zhize Li, Yufei Han, Bin Wang et al.USENIX Security 2025
- Enhancing Privacy Preservation in Federated Learning via Learning Rate PerturbationGuangnian Wan, Haitao Du, Xuejing Yuan, Jun Yang et al.ICCV 2023 · 2 citations
- Defending Against Data Reconstruction Attacks in Federated Learning: An Information Theory ApproachQi Tan, Qi Li, Yi Zhao, Zhuotao Liu et al.USENIX Security 2024 · 10 citations
- Find a Scapegoat: Poisoning Membership Inference Attack and Defense to Federated LearningWenjin Mo, Zhiyuan Li, Minghong Fang, Mingwei FangICCV 2025 · 3 citations
