FedDecouple is proposed, a phase-decoupled differentially private federated learning framework that is analytically suited for resource-constrained mobile devices and significantly outperforming client-side noised DP-SGD on MNIST and CIFAR-10.
Abstract
Differential privacy protection in federated learning faces the fundamental challenge of noise accumulation: noise added dispersedly by clients accumulates in variance during server-side aggregation, severely harming model convergence and accuracy. This paper proposes FedDecouple, a phase-decoupled differentially private federated learning framework that is analytically suited for resource-constrained mobile devices. The core innovation lies in decoupling the noise addition phase from the client computation phase—clients only upload clean gradients, while two auxiliary servers collaboratively generate and inject noise through a secure two-party MPC protocol. This design reduces the effective noise variance while eliminating the per-sample gradient computation burden on clients. Experimental results show that on MNIST, FedDecouple maintains 97.75% accuracy under strict privacy, significantly outperforming client-side noised DP-SGD with 94.0% accuracy. On CIFAR-10, it achieves 76.2% test accuracy, which is 13.4 percentage points higher than DP-SGD. FedDecouple’s total training time on both datasets is faster than Opacus and DP-SGD.
Federated Learning (FL) enables distributed training while keeping data local, but exchanged model updates can leak information through membership inference attacks. Differential privacy mitigates this risk via noise injection; however, aggressive DP regimes with strong noise can destabilize large models. An SNR-guided...
Mohammed Hamza, I. B. Sofi, Kuljeet Kaur et al.· International Conference on...· 0 citations
It is demonstrated that round-wise, layer-wise adaptation can improve the privacy-accuracy-efficiency trade-off of differentially private federated learning.
Wenjing Wei, Alla Jammine, F. Nait-Abdesselam· 0 citations
FedDyna is proposed, a novel framework that uses an adaptive noise injection mechanism to enhance privacy in non-IID data environments and effectively demonstrates the significant divergence between dynamic and static noise under non-IID settings.
Guijuan Wang, Zhiyu Zuo, An-Ming Dong et al.· 0 citations
i-FedLoRA provides privacy guarantees, improves model accuracy by up to 3.8%, and expedites training by 1.37-2.23×, and facilitates heterogeneous LoRA aggregation that selectively prioritizes high-confidence knowledge to filter DP-induced noise, thereby achieving robust knowledge transfer.
Nan Yan, Yu-Qing Li, Xiong Wang et al.· Proceedings of the 32nd ACM...· 0 citations
Federated Learning (FL) avoids centralizing raw data, but server-side access to per-client updates still creates a significant privacy risk because gradients can leak sensitive information through inversion and related attacks. A common defense is client-level Differential Privacy (DP), which reduces attack fidelity by...
Clifford N. Jones, Md Nahid Hasan, S. Wagle et al.· International Conference on...· 0 citations
Accurate client contribution evaluation is critical for sustainable federated learning and incentive design, yet existing methods face a trade-off between trust, complexity, and robustness. We show that validation-free, similarity-based metrics can suffer from a federated noise coupling effect, where historical low-qua...