ASDIA: An Adversarial Sample to Preserve Privacy Program in Federated Learning
Shujuan Tian, Yi Tan, Han Wang, Haolin Liu, Zhetao Li · IEEE Transactions on Dependable and Secure Computing · 2025
Federated learning enables training across multiple entities while ensuring data security and the effectiveness of knowledge dissemination. Despite its benefits, it remains susceptible to privacy breaches by both external and internal adversaries, who may exploit data or model parameters to glean sensitive participant information or disrupt the training process, thus compromising participant privacy and security. This paper proposes a novel methodology, Adversarial Samples for Defense Inference Attack (ASDIA), aimed at dual protection of data privacy and model robustness within federated learning through adversarial samples and gradient reconstruction. ASDIA includes gradient processing approach before uploading: initially identifying privacy-sensitive gradient, followed by the injection of well-calibrated noise to these gradients. This method not only obfuscates the adversary's classification demarcations but also aids in model performance recovery, all the while maintaining computational efficiency. ASDIA reduces the efficacy of attacks to near-random guessing levels and shows better balance between the model utility and privacy protection compared to the most advanced defense strategies. Additionally, regarding model performance, ASDIA proves its merit across diverse datasets under overfitting and non-overfitting scenarios.