The Federation Strikes Back: A Survey of Federated Learning Privacy Attacks, Defenses, Applications, and Policy Landscape

šŸ“… 2024-05-06
šŸ“ˆ Citations: 1
✨ Influential: 0
šŸ“„ PDF
šŸ¤– AI Summary
While federated learning (FL) avoids uploading raw data, model updates—particularly gradients—remain vulnerable to privacy attacks such as gradient/model inversion and membership inference, risking sensitive training data leakage. Method: This paper systematically surveys privacy attacks in FL, analyzing their feasibility under realistic constraints (e.g., non-IID data, few clients); evaluates limitations of mainstream defenses—including differential privacy and secure aggregation; and integrates industrial deployment cases with global regulatory frameworks (GDPR, CCPA). Contribution/Results: We propose the first FL privacy risk taxonomy unifying adversarial theory, empirical failure analysis, and compliance requirements. Innovatively, we introduce deployment-oriented dimensions for evaluating defense effectiveness and deliver a trustworthy FL implementation roadmap—balancing model utility and privacy guarantees—alongside a policy alignment guide for regulatory compliance.

Technology Category

Application Category

šŸ“ Abstract
Deep learning has shown incredible potential across a wide array of tasks, and accompanied by this growth has been an insatiable appetite for data. However, a large amount of data needed for enabling deep learning is stored on personal devices, and recent concerns on privacy have further highlighted challenges for accessing such data. As a result, federated learning (FL) has emerged as an important privacy-preserving technology that enables collaborative training of machine learning models without the need to send the raw, potentially sensitive, data to a central server. However, the fundamental premise that sending model updates to a server is privacy-preserving only holds if the updates cannot be"reverse engineered"to infer information about the private training data. It has been shown under a wide variety of settings that this privacy premise does not hold. In this survey paper, we provide a comprehensive literature review of the different privacy attacks and defense methods in FL. We identify the current limitations of these attacks and highlight the settings in which the privacy of ann FL client can be broken. We further dissect some of the successful industry applications of FL and draw lessons for future successful adoption. We survey the emerging landscape of privacy regulation for FL and conclude with future directions for taking FL toward the cherished goal of generating accurate models while preserving the privacy of the data from its participants.
Problem

Research questions and friction points this paper is trying to address.

Explores privacy attacks and defenses in federated learning.
Identifies limitations and vulnerabilities in FL privacy mechanisms.
Surveys FL applications and regulatory landscape for future adoption.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Federated learning enables collaborative model training.
Privacy attacks and defenses in FL analyzed.
FL applications and privacy regulations surveyed.
šŸ”Ž Similar Papers
No similar papers found.
Joshua C. Zhao
Joshua C. Zhao
Graduate Student at Purdue University
Federated LearningAdversarial Machine LearningSecurity & Privacy
Saurabh Bagchi
Saurabh Bagchi
Electrical & Computer Engineering, Computer Science; Director Army A2I2 & NSF CHORUS; Purdue
Distributed SystemsDependable ComputingInternet of Things
S
S. Avestimehr
University of Southern California and FedML, United States of America
K
Kevin S. Chan
DEVCOM Army Research Laboratory, United States of America
S
S. Chaterji
Purdue University and KeyByte, United States of America
D
Dimitris Dimitriadis
Amazon, United States of America
J
Jiacheng Li
Purdue University, United States of America
Ninghui Li
Ninghui Li
Professor of Computer Science, Purdue University
Privacy
A
Arash Nourian
Amazon, United States of America
H
Holger Roth
NVIDIA, United States of America