Privacy‐Preserving Hierarchical Federated Learning With Front‐Loaded Differential Privacy Mechanism
Hashan Ratnayake, Lin Chen, Xiaofeng Ding · Concurrency and Computation Practice and Experience · 2025
ABSTRACT Differential privacy is a widely recognized approach for enhancing privacy in federated learning by preventing sensitive information leakage during model training and deployment. These mechanisms typically bound the sensitivity of model updates through gradient or model parameter clipping, followed by noise injection to achieve formal privacy guarantees. However, achieving stronger privacy guarantees necessitates more noise, which can adversely impact model utility. Although various clipping and noise‐adding mechanisms have been explored in client‐level differential privacy, their comparative effectiveness within hierarchical federated learning remains underexplored. This study addresses this gap by systematically evaluating three primary clipping and noise‐adding approaches within a three‐tier hierarchical federated learning framework. The evaluation was conducted using two distinct neural networks trained on federated datasets derived from benchmark datasets. Each mechanism was assessed under three different noise levels, with performance measured by test accuracy and convergence behavior across global rounds. The results indicate that front‐loaded differential privacy mechanisms, such as clipping gradients and adding noise to either the clipped gradients or model parameters, achieve better convergence and model utility across varying noise scales and data distributions than the approach based on clipping and perturbing model parameter differences. These findings are particularly relevant to real‐world applications in privacy‐sensitive hierarchical settings, such as edge computing in healthcare and finance, where balancing privacy and utility is essential.