Deciphering the Interplay between Attack and Protection Complexity in Privacy-Preserving Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Xiaojin, Xu, Mingcong, Li, Yiming, Chen, Wei, Yang, Qiang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915448089477120
author Zhang, Xiaojin
Xu, Mingcong
Li, Yiming
Chen, Wei
Yang, Qiang
author_facet Zhang, Xiaojin
Xu, Mingcong
Li, Yiming
Chen, Wei
Yang, Qiang
contents Federated learning (FL) offers a promising paradigm for collaborative model training while preserving data privacy. However, its susceptibility to gradient inversion attacks poses a significant challenge, necessitating robust privacy protection mechanisms. This paper introduces a novel theoretical framework to decipher the intricate interplay between attack and protection complexities in privacy-preserving FL. We formally define "Attack Complexity" as the minimum computational and data resources an adversary requires to reconstruct private data below a given error threshold, and "Protection Complexity" as the expected distortion introduced by privacy mechanisms. Leveraging Maximum Bayesian Privacy (MBP), we derive tight theoretical bounds for protection complexity, demonstrating its scaling with model dimensionality and privacy budget. Furthermore, we establish comprehensive bounds for attack complexity, revealing its dependence on privacy leakage, gradient distortion, model dimension, and the chosen privacy level. Our findings quantitatively illuminate the fundamental trade-offs between privacy guarantees, system utility, and the effort required for both attacking and defending. This framework provides critical insights for designing more secure and efficient federated learning systems.
format Preprint
id arxiv_https___arxiv_org_abs_2508_11907
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Deciphering the Interplay between Attack and Protection Complexity in Privacy-Preserving Federated Learning
Zhang, Xiaojin
Xu, Mingcong
Li, Yiming
Chen, Wei
Yang, Qiang
Cryptography and Security
Artificial Intelligence
Federated learning (FL) offers a promising paradigm for collaborative model training while preserving data privacy. However, its susceptibility to gradient inversion attacks poses a significant challenge, necessitating robust privacy protection mechanisms. This paper introduces a novel theoretical framework to decipher the intricate interplay between attack and protection complexities in privacy-preserving FL. We formally define "Attack Complexity" as the minimum computational and data resources an adversary requires to reconstruct private data below a given error threshold, and "Protection Complexity" as the expected distortion introduced by privacy mechanisms. Leveraging Maximum Bayesian Privacy (MBP), we derive tight theoretical bounds for protection complexity, demonstrating its scaling with model dimensionality and privacy budget. Furthermore, we establish comprehensive bounds for attack complexity, revealing its dependence on privacy leakage, gradient distortion, model dimension, and the chosen privacy level. Our findings quantitatively illuminate the fundamental trade-offs between privacy guarantees, system utility, and the effort required for both attacking and defending. This framework provides critical insights for designing more secure and efficient federated learning systems.
title Deciphering the Interplay between Attack and Protection Complexity in Privacy-Preserving Federated Learning
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2508.11907