acceptodds
Under review as a conference paper at ICLR 2027

SpecSIA: Reliable Source Inference in Federated Learning via Adaptive Spectral Filtering

Abstract

Federated Learning (FL) enables collaborative model training without directly sharing raw data, yet client-specific updates can still reveal which client contributed a target sample, exposing FL to Source Inference Attack (SIA). Existing passive attacks typically attribute the target to the client model with the lowest prediction loss, which faces two limitations: first, global aggregation propagates target-relevant knowledge across clients, obscuring each client’s original contribution. Second, source attribution can be unstable across diverse federated configurations. Therefore, we propose Spectral Contribution-based Source Inference Attack (SpecSIA), which estimates target-relevant client contributions from current-round updates rather than relying on endpoint prediction loss. By combining normalized contribution attribution with adaptive spectral filtering, SpecSIA improves stability across communication rounds and federated settings. The attack operates using only information available in the current communication round and requires neither local optimization trajectories nor historical client updates. We evaluate source inference from four complementary perspectives: attack effectiveness, temporal reliability, statistical reliability across repeated runs, and cross-configuration consistency. Compared with the conventional loss-based attack, SpecSIA improves mean attack success rate (ASR) by up to 51.88% and reduces temporal variation by up to 54.34%, while maintaining competitive performance across heterogeneous federated configurations.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.