Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks

📅 2026-09-02
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究针对车辆边缘网络中联邦学习的隐私泄露问题,通过分析惯性测量数据推断客户端身份,并提出剪裁加噪声防御方法以保护隐私。
📝 Abstract
As vehicular networks move toward 5G/6G edge intelligence, federated learning (FL) is widely promoted as a privacy-preserving way for vehicles and infrastructure to train shared models without exposing raw sensor data. Yet the updates clients transmit still leak enough information to identify who sent them, which threatens the anonymity that safety-critical V2X applications assume and adds to existing concerns over adversarial ML, model poisoning, and backdoor attacks. We study server-side client identity inference from transmitted weight deltas using inertial (IMU) measurements, evaluated on the UCI Human Activity Recognition (HAR) benchmark as an accessible proxy for the IMU streams produced onboard connected vehicles. Across five attack classifiers and five non-IID partitions, an honest-but-curious server recovers client identity with near-perfect accuracy (approximately 1.000) from undefended updates, confirming a concrete identifiability risk. We then quantify the privacy-utility trade-off of a lightweight clip-then-noise defense by sweeping Gaussian noise (sigma in {0.00, 0.05, 0.10, 0.20, 0.50, 1.00}) at fixed clipping (C=1.0), and report formal (epsilon, delta)-DP budgets through Renyi accounting. A practical region (sigma in [0.1, 0.2]) drives attack accuracy to near-random while costing under 5% relative FL accuracy. Ensemble FL supplies complementary structural privacy with a 1/K anonymity-set bound and no noise penalty. Results are supported by cryptographic (SHA-256) train/evaluation gradient disjointness, three seeds, and a count-normalized attacker-advantage metric. We position HAR explicitly as a proxy and discuss what validation on true vehicular telemetry would require.
Problem

Research questions and friction points this paper is trying to address.

Federated Learning
Privacy Leakage
Client Identity Inference
Vehicular Edge Networks
Inertial Sensing
Innovation

Methods, ideas, or system contributions that make the work stand out.

federated learning
client identity inference
clip-then-noise defense
differential privacy
ensemble FL
A
Ali Akarma
AI Center, Faculty of Computer and Information Systems, Islamic University of Madinah, Madinah 42351, Saudi Arabia; AI V&V Lab, King Fahd University of Petroleum and Minerals, Dhahran 31261, Saudi Arabia
Toqeer Ali Syed
Toqeer Ali Syed
PHD, Full Professor, Islamic University of Al Madinah Al Munawara
SecurityBlockchainAIMachine LearningDeep Learning and Cloud Computing
M
Muhammad Khan
School of Computer Science and Creative Technologies, University of the West of England, Bristol BS16 1QY, U.K.
Q
Qurat-ul-ain Mastoi
School of Computer Science and Creative Technologies, University of the West of England, Bristol BS16 1QY, U.K.
A
Adeel Ahmad
AI Center, Faculty of Computer and Information Systems, Islamic University of Madinah, Madinah 42351, Saudi Arabia