Label Distribution Inference Attack and Directional Defense on Prototypes in Federated Learning
Abstract
Prototype-based federated learning has emerged as an effective approach for addressing model heterogeneity by enabling clients with diverse architectures to collaborate through the exchange of per-class mean feature embeddings. Although prototypes are generally considered privacy-preserving, we show that they can reveal sensitive information about clients' label distributions. Specifically, we identify a geometric vulnerability: local prototypes exhibit stronger angular alignment with global prototypes for classes with more local samples, making prototype alignment an informative indicator of class frequency. Motivated by this observation, we propose the Prototype-Based Label Distribution Inference Attack (PLIA), which infers per-client label distributions solely from shared prototypes by exploiting this geometric property. To mitigate this privacy risk, we further introduce Directional Prototype Perturbation (DPP), a defense mechanism that applies orthogonal perturbations with randomized per-class budgets to disrupt this leakage signal. Experiments across five benchmark datasets show that PLIA outperforms or matches baseline attacks, while DPP effectively reduces the label-distribution leakage PLIA exploits with only a marginal impact on model performance.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.