acceptodds
Under review as a conference paper at ICLR 2027

LOPA: Learning Local Subspaces for Privacy Protection in Split Federated Learning

Abstract

Split Federated Learning (SFL) reduces the computational burden on clients through collaborative training between clients and a server. However, an honest-but-curious server can still reconstruct private images from uploaded intermediate representations. Existing defenses limit information exposure through activation dropping, quantization, or perturbation, but these operations do not necessarily suppress reconstruction-relevant information while preserving information needed for classification, and stronger restrictions may degrade task performance. We observe that low-rank channel projection combined with normalization and spatial pooling can reduce reconstruction quality, but random selection of subspace directions does not consistently preserve classification accuracy. To address this issue, we propose LOPA (Local Privacy-Aware Subspace Adaptation), which uses only local client data to initialize a task-relevant subspace based on between-class and within-class scatter statistics. It then calibrates the subspace using classification loss and distance correlation to preserve task-discriminative information while reducing the statistical dependence of representations on raw inputs. The clients' orthogonal projection matrices are aggregated into a shared subspace before training, which remains fixed during online training to filter uploaded representations without further subspace optimization. Experiments on CelebA, CIFAR-10, and FMNIST show that LOPA substantially degrades reconstruction quality under both the FORA and Inverse-Network attacks. Unlike the compared defenses, which trade accuracy for protection, LOPA matches undefended SFL on all three datasets. Furthermore, subspace initialization takes only seconds and requires less memory than client-side training itself.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.