PPFL: Privacy-Preserving Federated Learning Based on Differential Privacy and Personalized Data Transformation
Jiali Han, Liangliang Wang, Zhiquan Liu, Baodong Qin, Kai Zhang, Weiwei Li · IEEE Internet of Things Journal · 2025
Federated learning (FL) prevents direct exposure of raw data. However, it remains vulnerable to privacy and security threats such as inference and poisoning attacks. Traditional differential privacy (DP) methods utilize noise injection to mitigate these attacks, which inherently degrades the accuracy of the model. In this paper, we propose a robust FL framework with two alternative effective defense mechanisms to enhance privacy preservation for various scenarios. We first propose a dual-layer client-server collaborative differential privacy (CLDP). Clients utilize adaptive local differential privacy (LDP) for data privacy, while the server uses central differential privacy (CDP) on the global model to mitigate poisoning attacks. Second, we propose enhanced central differential privacy (ECDP), a layer-specific protection mechanism that strategically injects targeted noise into non-batch normalization layers to further preserve data privacy. To mitigate noise-induced model performance degradation, our solution combines personalized data transformation and gradient sparsification, effectively alleviating both non-IID data distribution skew and cumulative noise effects. Architecturally, we decentralize the federated learning system through edge node integration, thereby eradicating single points of failure. Experimental results demonstrate that our framework achieves a superior accuracy-privacy trade-off under strict privacy constraints, providing robust protection without compromising practical utility.