Return
Privacy attack against federated tensor decomposition-based models
DOI:10.1080/24725854.2026.2637906.png)
Abstract
En 中文
Federated adaptations of popular dimensionality reduction methods, such as tensor decomposition, have been widely implemented to address data transmission constraints and enable privacy-sensitive sharing across distributed systems. Federated learning (FL) typically involves training models collaboratively across multiple sites with a global server or aggregator while keeping raw data decentralized. While these methods often claim to preserve privacy through various mechanisms, we show that the shared information essential for FL can be exploited to reconstruct local sites' private data. Furthermore, models that achieve better approximations to the true data and more effective FL approaches are increasingly vulnerable to attacks. We propose a novel attention-based privacy attack framework, along with theoretical analysis that quantifies privacy leakage using mutual information and entropy, to assess the vulnerability of federated tensor decomposition-based models, specifically Tucker decomposition. Simulations on synthetic three-dimensional point clouds and two case studies on healthcare correlation tensors and facial images demonstrate the effectiveness of our approach, underscoring the need for stronger privacy measures in federated analytics.
Keywords:
Privacy attack
federated learning
tensor decomposition
attention mechanism
mutual information
Journal
IF:
2.3
Papers:
85
Citations:
1.9K

