acceptodds
Under review as a conference paper at ICLR 2027

Retention is Leakage: Forgetting Does Not Confer Privacy in Federated Continual Learning

Abstract

Federated continual learning is often presented as private by design. Clients keep their raw data, and the data of an early task is assumed to fade from the system as the model forgets it. We test this assumption against an adversary who observes every broadcast rather than only the final model. The assumption fails in two ways. First, forgetting does not remove leakage. On CIFAR-100 and ImageNet-R, six further tasks of plain federated averaging erase about three quarters of the above-chance accuracy on an early task. The transcript still holds 87% and 97% of the above-chance membership leakage about that task. Second, retention is leakage. Every anti-forgetting mechanism we test preserves most of the accuracy and keeps or amplifies leakage. Exemplar replay raises above-chance membership leakage by a factor of 2.6 to 4.7 over six tasks. The factor grows with the share of client data that the buffer stores. A method that retains exact second-moment statistics exposes members with a true positive rate of at least 0.92 at a 1% false positive rate. Secure aggregation does not change this. We explain both failures with a lifelong accounting framework. It names the unit of privacy, records which releases read each datum, and separates retention operators that read old data again from operators that do not. Only the second kind admits a privacy cost that is independent of the length of the stream. We build a retention operator of that kind, which retains the release rather than the data. Under example-level privacy at it reaches 81% accuracy on CIFAR-100, against 88% without privacy, and a likelihood-ratio audit finds no leakage above chance.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.