MaxModShift: Model Privacy via Designed Shifts

📅 2026-08-10
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the privacy threat in federated learning where an eavesdropper infers the global model by observing transmitted data. To counter this, the authors propose MaxModShift—a scheme that, under transmit power constraints, deliberately perturbs model parameters to maximize the discrepancy between the global model learned by the central server and that reconstructed by the eavesdropper. The perturbation is designed to render the Fisher information matrix of the eavesdropper’s estimation problem singular, thereby preventing effective model recovery. Grounded in Fisher information analysis, MaxModShift integrates an optimization-driven parameter shifting strategy with low-power signal construction. It significantly outperforms existing approaches such as ModShift and noise injection, achieving superior model obfuscation while operating at lower transmit power and requiring less bandwidth for the secret key channel, thus offering simultaneous gains in privacy protection and resource efficiency.
📝 Abstract
Model learning by an eavesdropper is treated as an estimation problem in a federated environment. The Fisher Information Matrix for the eavesdropper's estimation problem is driven to singularity through a signaling design; this ensures that the eavesdropper cannot learn the model. Herein, the innovation of prior designs is that model shifts are designed to maximize the difference in the model learned by Eve and the central server while satisfying a transmission power constraint for the agents. Two shift schemes are provided. MaxModShift outperforms a prior ModShift design while requiring lesser transmission power. Compared to a noise injection scheme, MaxModShift performs better while requiring a lower bandwidth secret channel and a reduced average power consumption.
Problem

Research questions and friction points this paper is trying to address.

model privacy
federated learning
eavesdropping
Fisher Information Matrix
signaling design
Innovation

Methods, ideas, or system contributions that make the work stand out.

MaxModShift
Federated Learning
Model Privacy
Fisher Information Matrix
Power-Constrained Signaling
🔎 Similar Papers
No similar papers found.