This paper argues that federated learning should be evaluated as a privacy-enhancing framework rather than as a complete privacy guarantee, and proposes a comparat ive framework that asks what federated learning protects, what it still exposes, and which auxiliary mechanisms are needed in different application settings.
Abstract
Federated learning has become a major approach for training artificial intelligence systems when data is distributed across institutions, devices, or users. Its central appeal is that raw data can remain local while model updates are coordinated through a shared training process. This paper argues that federated learning should be evaluated as a privacy-enhancing framework rather than as a complete privacy guarantee. It first identifies key privacy risks, including model-update leakage, gradient inversion, membership inference, and risks created by malicious participants. It then classifies protection mechanisms into architectural choices, optimization design, differential privacy, secure aggregation, and deployment constraints. The paper proposes a comparat ive framework that asks what federated learning protects, what it still exposes, and which auxiliary mechanisms are needed in different application settings. Healthcare AI and mobile keyboard prediction are used as contrasting case studies: the former is typically cross-silo and institutionally governed, while the latter is cross- device and large-scale. The analysis concludes that federated learning is most effective when combined with explicit threat models, layered privacy protections, security controls, and governance arrangements.
The experiment showed that Autoencoder Based Federated Learning was a scalable, secure, and privacy-efficient solution to applications tailored for healthcare, finance, and other sensitive data environments.
Guman Singh Chauhan, venkata Surya Teja Gollapalli, Kannan Srinivasan et al.· Journal of Science & Technol...· 0 citations
FedE, a multi-precision, multi-source, heterogeneous privacy-preserving federated learning training method based on functional encryption that enhances numerical adaptation during ciphertext computation and prevents model parameter updates from easily compromising privacy in cross-institutional federated learning.
Weijia Liu, Junwen Deng, Hao Li et al.· Computers, Materials & C...· 0 citations
These findings demonstrate that the proposed framework provides an effective balance between privacy preservation, adversarial robustness, and trustworthy decentralized collaborative learning for secure AI-driven systems.
Durga Sivan, Uma Maheshwari Shanmugam, Sachnev Vasily et al.· Discover Artificial Intellig...· 0 citations
This survey examines KD-based FL through a privacy and security lens, and provides a precise framework for evaluating what KD-FL methods actually guarantee and what they only make harder for an adversary.
Hamza Reguieg, Essaid Sabir, M. El Kamili· IEEE Access· 0 citations
Machine learning systems use sensitive personal data to train and infer models, but developers are largely unaware of privacy attack vectors that evade conventional data security controls. This paper surveys the privacy threat landscape inherent to ML workflows, including membership inference attacks, model inversion a...
Pramod Prakash· International Journal of Int...· 0 citations
Related blog posts
MIT News · Artificial Intelligence· news.mit.eduOct 7, 2026
Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.
Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.
MIT News · Artificial Intelligence· news.mit.eduOct 6, 2026