Skip to content
Conference

Exploring Potential Vulnerabilities in Decomposed Convolutional Filters for Federated Learning

Jul 2026 · International Conference on Ubiquitous and Future Networks · pp. 95-97 · 0 citations · 13 references

Abstract

Federated Learning (FL) enables collaborative model training across distributed clients without directly sharing sensitive local data. However, the sharing of gradients or model updates still leaves the framework vulnerable to privacy breaches, notably Deep Leakage from Gradients (DLG). To counter such threats, recent methodologies like Decomposed Convolutional Filters (DCF) have been proposed. DCF attempts to mask the true gradients by decomposing convolution weights into Filter Atoms and Shared Atom Coefficients, exchanging only the Filter Atoms. In this paper, we explore a potential vulnerability in the DCF-based FL architecture. We provide a threat model and an attack scenario demonstrating how an honest-but-curious server could mathematically reconstruct a client’s local model. By evaluating the intermediate stage of the attack under various initialization and training scenarios, we provide empirical evidence that DCF inherently suffers from a critical trade-off between model utility and structural leakage, enabling potential data reconstruction.

View source

Similar papers

Conference Aug 2026

URP-FL: Robust and Personalized Federated Learning under Heterogeneous and Adversarial Conditions

Federated learning is appealing for privacy-sensitive network systems, yet its practical deployment remains hindered by the following three recurring challenges: (1) client drift under non-IID data, (2) vulnerability to corrupted updates, and (3) the communication cost of repeated model exchange. Most existing approach...

Hua Kun, Wei Wang · 0 citations
Preprint Aug 2026

TOFD: Target-Oriented Feature Decoupling against Poisoning Attacks in Split Federated Learning

Split Federated Learning (SFL) facilitates privacy-preserving collaborative training with reduced client-side overhead. However, its split architecture introduces unique attack surfaces, rendering it vulnerable to diverse poisoning attacks. Most existing defenses fail to exploit the split paradigm, limiting their abili...

Yu-Han Xie, Jing Huang, Chen Lyu · 0 citations
Open access Jul 2026

A Comprehensive Defense Framework Against Poisoning Backdoor Attacks in Federated Learning

This work employs the novel dimensionality reduction technique UMAP and a stringent filtering mechanism to effectively identify and exclude potential malicious participants without relying on traditional noise addition methods and demonstrates that the proposed method maintains high main task accuracy while effectively...

Chun-I Fan, Hsin-Yen Wang, Tomohiro Morikawa · 0 citations
#machine learning Preprint Sep 2026

Privacy-Preserving Split Learning for Federated LLM Fine-Tuning

This work addresses leakage through a learned obfuscate-and-recover scheme that protects participants' private datasets while still allowing an independently deployable model to be trained on the server side, making split-based federated LLM fine-tuning practically viable.

Heng Jin, Chao-Yu Zhang, He-Xuan Yu et al. · 1 citation
Preprint Aug 2026

FedLNS: Leverage LayerNorm Signature Modeling to Mitigate Adversarial Manipulation in Federated LLMs

FedLNS represents each client update through changes in trainable normalization-layer parameters and screens suspicious updates against a robust, history-aware cross-client reference, and achieves lower test perplexity than the strongest of six baselines for all three architectures under both IID (independently and ide...

Kai Li, Jong-Ik Park, Carlee Joe-Wong et al. · 0 citations
#machine learning Preprint Sep 2026

Fine-grained Distributed Backdoor Attacks in Federated Learning

Federated learning, as a privacy-preserving distributed machine learning paradigm, faces significant threats from backdoor attacks. Compared to centralized attacks, distributed backdoor attacks are more harmful but require more poisoned samples to compensate for the loss of trigger strength due to decomposition. Fixed...

Jian Wang, Hong Shen, Wei Ke et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.