CloakFL: Mitigating Global Model Exposure in Federated Learning via Convergence-Aware Proxy Distribution
Abstract
In federated learning, the server repeatedly sends the global model to participating clients for local training, exposing the model to the risk of leakage or redistribution outside the federation. Proxy Model Distribution (PMD) mitigates this risk by distributing intentionally degraded proxy models instead of the clean global model. Existing PMD methods, however, face a protection–convergence trade-off: stronger degradation reduces the proxy’s inference performance but impedes global convergence, whereas weaker degradation better preserves global convergence but provides weaker protection. We propose CloakFL, a PMD method that adds convergence-aware perturbations to the global model. CloakFL constructs perturbation directions derived from the previous round’s local training, enabling effective degradation with relatively small perturbations. It then scales each perturbation according to the target client’s latest update to better preserve global convergence. Through convergence analysis and experiments on CNN and Transformer architectures, we show that the performance of the proxy models remains substantially below that of the global model, while keeping the global model’s performance close to that of standard federated learning.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.