Local versus central differential privacy under final-model privacy attacks in low-client-count cross-silo federated learning

Federated learning reduces the need to centralize raw data, but does not prevent privacy leakage from client updates, aggregation messages, or the final released model. This work compares local differential privacy (LDP), central differential privacy (CDP), record-level differentially private stochastic gradient descent (DP-SGD), and secure aggregation (SecAgg) in a low-client-count cross-silo setting with full client participation, across four datasets spanning image classification, tabular binary classification, and two time-series forecasting tasks. The study separates training-time confidentiality from final-model leakage and evaluates the released models under two final-model privacy attacks, membership inference and targeted reconstruction. Under these attacks, SecAgg leaves final-model leakage essentially unchanged: it protects the confidentiality of per-client updates during training but provides no $$(\varepsilon ,\delta )$$ guarantee for the released model, and is therefore evaluated as a complementary training-time mechanism whose principal cost is a training-time overhead of approximately 49% to 106%, varying by dataset and client count. Differential privacy constrains final-model leakage more directly, but its practical value depends on the balance between privacy protection and retained utility. Across the evaluated configurations, record-level DP-SGD, implemented locally on each client by clipping and perturbing per-example gradients, preserved utility best, staying closest to the non-private baseline on every task and remaining usable on image classification, where both client-contribution-level mechanisms collapsed to chance-level accuracy. Among the client-level mechanisms, CDP matched or exceeded LDP at equal privacy budget, because under a single consistent accountant the two share the same noise calibration and LDP carries $$\sqrt{M}$$ more aggregate noise; the advantage of DP-SGD in turn follows from privacy amplification by subsampling, which lets it reach a given budget at roughly a tenth of the client-level noise. Under both final-model attacks the released models leaked little: membership inference stayed close to random guessing on the classification tasks, with a modest, temporally confounded elevation on the time-series tasks, and targeted reconstruction never improved on an uninformed baseline. These findings support selecting privacy-enhancing mechanisms according to the attacker model, trust assumptions, privacy unit, and acceptable utility loss, rather than by mechanism label alone.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-09-26
DOI
https://doi.org/10.1038/s41598-026-70584-5
Primary Topic
Privacy-Preserving Technologies in Data
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Local versus central differential privacy under final-model privacy attacks in low-client-count cross-silo federated learning

Oleksandr Lytvyn, Giang Nguyen, Hlib Kokin
Scientific Reports
Privacy-Preserving Technologies in Data
article

Local versus central differential privacy under final-model privacy attacks in low-client-count cross-silo federated learning

Oleksandr Lytvyn, Giang Nguyen, Hlib Kokin
article en

Abstract

Federated learning reduces the need to centralize raw data, but does not prevent privacy leakage from client updates, aggregation messages, or the final released model. This work compares local differential privacy (LDP), central differential privacy (CDP), record-level differentially private stochastic gradient descent (DP-SGD), and secure aggregation (SecAgg) in a low-client-count cross-silo setting with full client participation, across four datasets spanning image classification, tabular binary classification, and two time-series forecasting tasks. The study separates training-time confidentiality from final-model leakage and evaluates the released models under two final-model privacy attacks, membership inference and targeted reconstruction. Under these attacks, SecAgg leaves final-model leakage essentially unchanged: it protects the confidentiality of per-client updates during training but provides no $$(\varepsilon ,\delta )$$ guarantee for the released model, and is therefore evaluated as a complementary training-time mechanism whose principal cost is a training-time overhead of approximately 49% to 106%, varying by dataset and client count. Differential privacy constrains final-model leakage more directly, but its practical value depends on the balance between privacy protection and retained utility. Across the evaluated configurations, record-level DP-SGD, implemented locally on each client by clipping and perturbing per-example gradients, preserved utility best, staying closest to the non-private baseline on every task and remaining usable on image classification, where both client-contribution-level mechanisms collapsed to chance-level accuracy. Among the client-level mechanisms, CDP matched or exceeded LDP at equal privacy budget, because under a single consistent accountant the two share the same noise calibration and LDP carries $$\sqrt{M}$$ more aggregate noise; the advantage of DP-SGD in turn follows from privacy amplification by subsampling, which lets it reach a given budget at roughly a tenth of the client-level noise. Under both final-model attacks the released models leaked little: membership inference stayed close to random guessing on the classification tasks, with a modest, temporally confounded elevation on the time-series tasks, and targeted reconstruction never improved on an uninformed baseline. These findings support selecting privacy-enhancing mechanisms according to the attacker model, trust assumptions, privacy unit, and acceptable utility loss, rather than by mechanism label alone.

Scientific Reports
Slovak University of Technology in Bratislava (SK)
Peace, Justice and strong institutions
Openalex Percentile: Top 9%
Privacy-Preserving Technologies in Data
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.