Skip to content
#federated learning Open access

Local versus central differential privacy under final-model privacy attacks in low-client-count cross-silo federated learning

Sep 2026 · Scientific Reports
Privacy-Preserving Technologies in Data

Abstract

Federated learning reduces the need to centralize raw data, but does not prevent privacy leakage from client updates, aggregation messages, or the final released model. This work compares local differential privacy (LDP), central differential privacy (CDP), record-level differentially private stochastic gradient descent (DP-SGD), and secure aggregation (SecAgg) in a low-client-count cross-silo setting with full client participation, across four datasets spanning image classification, tabular binary classification, and two time-series forecasting tasks. The study separates training-time confidentiality from final-model leakage and evaluates the released models under two final-model privacy attacks, membership inference and targeted reconstruction. Under these attacks, SecAgg leaves final-model leakage essentially unchanged: it protects the confidentiality of per-client updates during training but provides no $$(\varepsilon ,\delta )$$ guarantee for the released model, and is therefore evaluated as a complementary training-time mechanism whose principal cost is a training-time overhead of approximately 49% to 106%, varying by dataset and client count. Differential privacy constrains final-model leakage more directly, but its practical value depends on the balance between privacy protection and retained utility. Across the evaluated configurations, record-level DP-SGD, implemented locally on each client by clipping and perturbing per-example gradients, preserved utility best, staying closest to the non-private baseline on every task and remaining usable on image classification, where both client-contribution-level mechanisms collapsed to chance-level accuracy. Among the client-level mechanisms, CDP matched or exceeded LDP at equal privacy budget, because under a single consistent accountant the two share the same noise calibration and LDP carries $$\sqrt{M}$$ more aggregate noise; the advantage of DP-SGD in turn follows from privacy amplification by subsampling, which lets it reach a given budget at roughly a tenth of the client-level noise. Under both final-model attacks the released models leaked little: membership inference stayed close to random guessing on the classification tasks, with a modest, temporally confounded elevation on the time-series tasks, and targeted reconstruction never improved on an uninformed baseline. These findings support selecting privacy-enhancing mechanisms according to the attacker model, trust assumptions, privacy unit, and acceptable utility loss, rather than by mechanism label alone.

View source

Similar papers

#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54
#machine learning Review Open access Jun 2014

Why Early-Stage Software Startups Fail: A Behavioral Framework

This state-of-practice investigation was performed using a literature review followed by a multiple-case study approach and presents how inconsistency between managerial strategies and execution can lead to failure by means of a behavioral framework.

Carmine Giardino, Xiaofeng Wang, P. Abrahamsson · 175 citations · ⚡19
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#machine learning Review Open access May 2016

Key Challenges in Software Startups Across Life Cycle Stages

It is found that what perceived as biggest challenges by software startups do vary across different life cycle stages, even though its significance decreases when the learning focuses of the startups move from problem to solution and their products mature.

Xiaofeng Wang, Henry Edison, Sohaib Shahid Bajwa et al. · 62 citations · ⚡6

Related blog posts

MIT News · Artificial Intelligence Oct 7, 2026

Discovering the value of humanistic inquiry

Students in MIT’s Concourse program delve deeply into the human condition, debate challenging questions, and learn to develop judgment about issues that can’t be quantified.

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.