United We Defend: Collaborative Membership Inference Defenses in Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Bai, Li, Liu, Junxu, Zhang, Sen, Zhang, Xinwei, Ye, Qingqing, Hu, Haibo
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908757275967488
author Bai, Li
Liu, Junxu
Zhang, Sen
Zhang, Xinwei
Ye, Qingqing
Hu, Haibo
author_facet Bai, Li
Liu, Junxu
Zhang, Sen
Zhang, Xinwei
Ye, Qingqing
Hu, Haibo
contents Membership inference attacks (MIAs), which determine whether a specific data point was included in the training set of a target model, have posed severe threats in federated learning (FL). Unfortunately, existing MIA defenses, typically applied independently to each client in FL, are ineffective against powerful trajectory-based MIAs that exploit temporal information throughout the training process to infer membership status. In this paper, we investigate a new FL defense scenario driven by heterogeneous privacy needs and privacy-utility trade-offs, where only a subset of clients are defended, as well as a collaborative defense mode where clients cooperate to mitigate membership privacy leakage. To this end, we introduce CoFedMID, a collaborative defense framework against MIAs in FL, which limits local model memorization of training samples and, through a defender coalition, enhances privacy protection and model utility. Specifically, CoFedMID consists of three modules: a class-guided partition module for selective local training samples, a utility-aware compensation module to recycle contributive samples and prevent their overconfidence, and an aggregation-neutral perturbation module that injects noise for cancellation at the coalition level into client updates. Extensive experiments on three datasets show that our defense framework significantly reduces the performance of seven MIAs while incurring only a small utility loss. These results are consistently verified across various defense settings.
format Preprint
id arxiv_https___arxiv_org_abs_2601_06866
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle United We Defend: Collaborative Membership Inference Defenses in Federated Learning
Bai, Li
Liu, Junxu
Zhang, Sen
Zhang, Xinwei
Ye, Qingqing
Hu, Haibo
Cryptography and Security
Membership inference attacks (MIAs), which determine whether a specific data point was included in the training set of a target model, have posed severe threats in federated learning (FL). Unfortunately, existing MIA defenses, typically applied independently to each client in FL, are ineffective against powerful trajectory-based MIAs that exploit temporal information throughout the training process to infer membership status. In this paper, we investigate a new FL defense scenario driven by heterogeneous privacy needs and privacy-utility trade-offs, where only a subset of clients are defended, as well as a collaborative defense mode where clients cooperate to mitigate membership privacy leakage. To this end, we introduce CoFedMID, a collaborative defense framework against MIAs in FL, which limits local model memorization of training samples and, through a defender coalition, enhances privacy protection and model utility. Specifically, CoFedMID consists of three modules: a class-guided partition module for selective local training samples, a utility-aware compensation module to recycle contributive samples and prevent their overconfidence, and an aggregation-neutral perturbation module that injects noise for cancellation at the coalition level into client updates. Extensive experiments on three datasets show that our defense framework significantly reduces the performance of seven MIAs while incurring only a small utility loss. These results are consistently verified across various defense settings.
title United We Defend: Collaborative Membership Inference Defenses in Federated Learning
topic Cryptography and Security
url https://arxiv.org/abs/2601.06866