MaxModShift: Model Privacy via Designed Shifts
2026-08-10 • Machine Learning
Machine LearningInformation Theory
AI summaryⓘ
The authors study how to stop an eavesdropper from learning a model in a federated learning setup by treating the eavesdropper's task as an estimation problem. They create special changes, called model shifts, that confuse the eavesdropper while keeping communication efficient and within power limits. Their new method, MaxModShift, improves on earlier designs by better preventing eavesdropping and using less transmission power. It also works better than adding noise and needs fewer resources like bandwidth and power.
federated learningeavesdroppingFisher Information Matrixmodel shiftsestimation problemtransmission power constraintnoise injectionbandwidthprivacy in machine learningsignal design
Authors
Nomaan A. Kherani, Urbashi Mitra
Abstract
Model learning by an eavesdropper is treated as an estimation problem in a federated environment. The Fisher Information Matrix for the eavesdropper's estimation problem is driven to singularity through a signaling design; this ensures that the eavesdropper cannot learn the model. Herein, the innovation of prior designs is that model shifts are designed to maximize the difference in the model learned by Eve and the central server while satisfying a transmission power constraint for the agents. Two shift schemes are provided. MaxModShift outperforms a prior ModShift design while requiring lesser transmission power. Compared to a noise injection scheme, MaxModShift performs better while requiring a lower bandwidth secret channel and a reduced average power consumption.