ISEP - DM – Engenharia de Inteligência Artificial
URI permanente para esta coleção:
Navegar
Percorrer ISEP - DM – Engenharia de Inteligência Artificial por orientador "Amorim, Ivone de Fátima da Cruz"
A mostrar 1 - 1 de 1
Resultados por página
Opções de ordenação
- Topology-dependent privacy risks in decentralized federated learningPublication . GOUVEIA, JOSÉ INÁCIO ANTUNES DE; Pereira, Isabel Cecília Correia da Silva Praça Gomes; Amorim, Ivone de Fátima da CruzFederated Learning (FL) has established itself as a leading paradigm for collaborative machine learning, allowing participants to train models collectively without sharing their private data. Despite its privacy-preserving design, the periodic exchange of model updates leaves these systems vulnerable to information leakage. Notable threats include Membership Inference Attacks (MIA), which exploit model overfitting to determine if specific data samples were used during training, and Gradient Inversion Attacks (GIA), which attempt to reconstruct the exact training images from shared gradients. While existing literature has proposed various active defenses and investigated privacy risks within star and mesh network topologies, a systematic evaluation of how attack effectiveness evolves across training rounds over a diverse spectrum of network topologies remains a critical research gap. This dissertation presents a comprehensive empirical analysis of how different network topologies influence data privacy in centralized and decentralized FL systems over time. By isolating the network topology as the primary variable, we evaluate the vulnerability of six distinct topologies, star, tree, line, ring, full mesh, and partial mesh, against three MIA variants and a GIA. The experiments were conducted using the MNIST and CIFAR10 datasets under both Independent and Identically Distributed and Non-Independent and Identically Distributed (Non-IID) data distributions to capture the temporal evolution of these attacks across the training rounds. Our findings show that network topologies fundamentally dictate the severity and localization of privacy leakage. For instance, intermediate aggregation in the tree topology acts as a native privacy shield, effectively hiding memorized features from a central root node, though it inadvertently shifts the primary risk to intermediate edge nodes. Furthermore, the analysis reveals that extreme data heterogeneity (Non-IID) significantly aggravates vulnerabilities across all topologies, heavily increasing MIA and GIA success rates on complex visual tasks. Moreover, the results establish that restricting an adversary’s awareness of the broader network topology severely impedes their ability to accurately execute GIA, as successful data reconstruction depends heavily on precise knowledge of the aggregation phase in federated systems. Ultimately, this research highlights that network topology can be strategically leveraged as passive defense mechanisms.
