Latest Findings · ASI Lab

FedDC: dual-layer protection that keeps federated learning accurate against black-box and white-box attacks

Combining differential privacy with chaos-based parameter scrambling — applied selectively to sensitive layers — preserves accuracy while driving stolen-model and inversion attacks to near-random.

Yihan Liao, Jacky W. Keung, Jingyu Zhang, Yurou Dai
Agentic Software Intelligence Research Lab · Department of Computer Science, City University of Hong Kong
Journal of Information Security & Applications · 2026

FedDC pairs differential privacy with a chaos-logistic-map scrambler, protecting only sensitive layers (not the whole model). Against black-box theft it drags accuracy to 9–12%; against white-box model inversion it raises reconstruction error dramatically — all with under 2.3–5% per-round overhead.

FedDC: Efficient protection scheme based on chaotic system in federated learning
Fig. 8. Scrambling and inverse scrambling time with varying numbers of protected batches in layer Vc (MNIST).

Why it matters

Federated learning enables collaborative model training without sharing raw data, yet model parameters still leak sensitive information; efficient protection schemes are needed.

Key findings

FedDC

What it means for practitioners

Where privacy matters but accuracy and compute budget do too, FedDC shows you need not pay the cost of secure aggregation: selective layer protection plus a lightweight scrambler keeps accuracy while neutralizing theft and inversion.

Get the paper & cite it

Download full PDF ↓ View at DOI

Official citation: Yihan Liao, Jacky W. Keung, Jingyu Zhang, Yurou Dai (2026). FedDC: Efficient protection scheme based on chaotic system in federated learning. Journal of Information Security and Applications. DOI: 10.1016/j.jisa.2026.104559.

Federated learning Differential privacy Privacy-preserving Chaotic system Model inversion Parameter scrambling Machine learning security