arrow
Return

Privacy attack against federated tensor decomposition-based models

delete2026-03-01
delete0
PRE
AI
Y
Yichen Ma
B
Biehler, Michael
S
Shi, Jianjun *
DOI:10.1080/24725854.2026.2637906delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Federated adaptations of popular dimensionality reduction methods, such as tensor decomposition, have been widely implemented to address data transmission constraints and enable privacy-sensitive sharing across distributed systems. Federated learning (FL) typically involves training models collaboratively across multiple sites with a global server or aggregator while keeping raw data decentralized. While these methods often claim to preserve privacy through various mechanisms, we show that the shared information essential for FL can be exploited to reconstruct local sites' private data. Furthermore, models that achieve better approximations to the true data and more effective FL approaches are increasingly vulnerable to attacks. We propose a novel attention-based privacy attack framework, along with theoretical analysis that quantifies privacy leakage using mutual information and entropy, to assess the vulnerability of federated tensor decomposition-based models, specifically Tucker decomposition. Simulations on synthetic three-dimensional point clouds and two case studies on healthcare correlation tensors and facial images demonstrate the effectiveness of our approach, underscoring the need for stronger privacy measures in federated analytics.
Keywords:
Privacy attack
federated learning
tensor decomposition
attention mechanism
mutual information

Journal

IISE Transactions cover
IISE Transactions
IF:
2.3
Papers:
85
Citations:
1.9K

Organization

G
georgia institute of technology
Scholars:
2.0K
Papers: 1.0K
Citations: 0
U
university system of georgia
Scholars:
7.3W
Papers: 6.5W
Citations: 101