FedDC: dual-layer protection that keeps federated learning accurate against black-box and white-box attacks
Combining differential privacy with chaos-based parameter scrambling — applied selectively to sensitive layers — preserves accuracy while driving stolen-model and inversion attacks to near-random.
FedDC pairs differential privacy with a chaos-logistic-map scrambler, protecting only sensitive layers (not the whole model). Against black-box theft it drags accuracy to 9–12%; against white-box model inversion it raises reconstruction error dramatically — all with under 2.3–5% per-round overhead.
Why it matters
Federated learning enables collaborative model training without sharing raw data, yet model parameters still leak sensitive information; efficient protection schemes are needed.
Key findings
- Competitive accuracy At ε=60: ~98.76% MNIST, ~85.44% Fashion-MNIST, ~74.23% CIFAR-10, ~89.26% Amazon Review; even at stricter ε=10 MNIST stays above 90%.
- Beats DP-only on CIFAR-10 FedDC (74.23%) substantially outperforms PE-DPFL (54.21%), ALI-DPFL (55.67%) and hybrid ADPHE-FL (71.04%); combining DP with a scaling mechanism alleviates noise-induced utility loss.
- Black-box theft neutralized Protecting conv, FC, or both layers drives stolen-model accuracy to near random guessing (9–12%) on MNIST/Fashion-MNIST; AR drops from 13.99% to 3.34% as more layers are protected.
- White-box inversion degraded MAE rises markedly with protection (MNIST 0.03→1.92→2.39; CIFAR-10 0.62→9.14→9.93), indicating much worse reconstruction quality.
- Very low overhead Scrambling + inverse scrambling is under 2.3% of round time for CNN datasets and under 5% for BERT, a lightweight alternative to heavy cryptographic methods.
FedDC
- Dual-layer protection: client-side Laplace differential privacy (clipping bound C bounds sensitivity) plus chaos-based parameter scrambling using a logistic map x_{n+1} = μ x_n(1 − x_n).
- Selective layer-aware protection: scrambles only sensitive layers (first conv + FC in CNN; value projection matrix W_v in BERT) instead of uniform whole-model protection.
- Server aggregates via FedAvg directly; clients inverse-scramble locally after broadcast — no heavy crypto, preserving FedAvg compatibility.
- Threat model: honest-but-curious, non-colluding server/clients; evaluated against both black-box prediction and white-box model-inversion attacks.
What it means for practitioners
Where privacy matters but accuracy and compute budget do too, FedDC shows you need not pay the cost of secure aggregation: selective layer protection plus a lightweight scrambler keeps accuracy while neutralizing theft and inversion.
Get the paper & cite it
Official citation: Yihan Liao, Jacky W. Keung, Jingyu Zhang, Yurou Dai (2026). FedDC: Efficient protection scheme based on chaotic system in federated learning. Journal of Information Security and Applications. DOI: 10.1016/j.jisa.2026.104559.