FL-SQMPC: Secure Quantized Aggregation for Mitigating Gradient Inversion Attacks in Federated IoT Intrusion Detection
Abstract
Federated Learning (FL) enables collaborative model training without centralizing raw data, but the exchange of model updates exposes clients to gradient inversion attacks (GIAs), which can reconstruct private training data from communicated gradients alone. To address this issue, we propose FL-SQMPC, a secure aggregation protocol that combines layer-wise mixed-precision quantization, fixed-point encoding, and additive secret sharing over a prime field. Under a noncollusion assumption on the secure aggregators, the secret-sharing layer provides information-theoretic hiding of each client update, while mixed-precision quantization reduces the precision and size of the transmitted update representation. We evaluate FL-SQMPC on Bot-IoT, ToN-IoT, and CICIoT2023 under Independent and Identically Distributed (IID) and non-IID partitions, comparing against vanilla FL, Differential Privacy, Homomorphic Encryption, and recent baselines, including CIDIoT. Under a TabLeak-based reconstruction adversary that observes the protected quantized update in the stronger colluding-participant setting, FL-SQMPC keeps tabular feature-recovery accuracy below vanilla FL across most evaluated settings. On predictive utility, FL-SQMPC matches vanilla FL within reproducibility noise and outperforms CIDIoT by up to $+5.54\%$ across the non-IID multiclass settings, while incurring substantially lower computational overhead than HE and CIDIoT. These results demonstrate a practical privacy–utility–efficiency tradeoff for resource-constrained IoT deployments.