Federated Learning as a Privacy-Enhancing Framework: Risks, Protection Mechanisms, and Applications
Federated learning has become a major approach for training artificial intelligence systems when data is distributed across institutions, devices, or users. Its central appeal is that raw data can remain local while model updates are coordinated through a shared training process. This paper argues that federated learning should be evaluated as a privacy-enhancing framework rather than as a complete privacy guarantee. It first identifies key privacy risks, including model-update leakage, gradient inversion, membership inference, and risks created by malicious participants. It then classifies protection mechanisms into architectural choices, optimization design, differential privacy, secure aggregation, and deployment constraints. The paper proposes a comparat ive framework that asks what federated learning protects, what it still exposes, and which auxiliary mechanisms are needed in different application settings. Healthcare AI and mobile keyboard prediction are used as contrasting case studies: the former is typically cross-silo and institutionally governed, while the latter is cross- device and large-scale. The analysis concludes that federated learning is most effective when combined with explicit threat models, layered privacy protections, security controls, and governance arrangements.