Privacy-Preserving Decentralized Federated Learning via Explainable Adaptive Differential Privacy

arXiv:2509.10691 · cs.CR, cs.AI · Submitted 2026-08-16 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.

Tom: Next we'll be talking about the paper "Privacy-Preserving Decentralized Federated Learning via Explainable Adaptive Differential Privacy".

Jane: The paper was written by Fardin Jalil Piran, Zhiling Chen, Yang Zhang, Qianyu Zhou, Jiong Tang et al. from University of Connecticut.

Tom: Stay tuned as we take you through the paper and discuss its implications.

Title: Tom: Alright, welcome back to the show, everybody. We’ve got a paper on the table that I genuinely couldn’t stop thinking about after I read it. It’s called “Privacy-Preserving Decentralized Federated Learning via Explainable Adaptive Differential Privacy.”

Jane: And Tom, I have to say, that title is a mouthful, but every single word in it is doing heavy lifting. We’re talking about federated learning, which is when multiple devices train a shared model without ever sending their raw data to a central server.

Tom: Right, and the twist here is that they’ve made it *decentralized*. So there’s no central server at all. Clients talk directly to each other, like a peer-to-peer network. That removes the single point of failure that regular federated learning has.

Jane: But here’s the problem they’re tackling. Even without a central server, the model updates that clients share can leak private information. An attacker can reverse-engineer those updates to reconstruct training data or figure out if a specific person’s data was in the training set.

Tom: And that’s where differential privacy comes in. You add carefully calibrated noise to the updates so that no single person’s data can be distinguished. But the classic way of doing that in a decentralized setting is kind of brute force.

Jane: Exactly. The old approach assumes every client has to add a full dose of noise every single time, because nobody knows how much noise has already been added by previous clients. It’s like everyone assuming the room is completely dark and turning on their flashlight at full brightness, even though the room is already lit.

Tom: That’s a great analogy, Jane. And that’s why this paper is so clever. They built a system called PrivateDFL that actually tracks the cumulative noise across all clients and rounds. So each client only adds the *difference* between what’s needed and what’s already there.

Jane: So instead of everyone shouting at full volume, each person just whispers enough to be heard. That keeps the privacy guarantee intact but doesn’t destroy the model’s accuracy with excessive noise.

Tom: And the authors are from the University of Connecticut. They’ve got a team of researchers in mechanical engineering and manufacturing, which is interesting because they’re clearly thinking about real-world industrial applications, not just theoretical math.

Jane: Right, and they’re using something called hyperdimensional computing as the backbone model, which is super lightweight and noise-tolerant. We’ll get into that in a bit, but the big picture here is that they’re making privacy protection both stronger and more transparent.

Tom: Transparent is the key word. They call it “explainable” differential privacy. You can actually audit how much noise has been added and verify the privacy budget is being respected. That’s huge for trust.

Jane: And that’s what I love about this paper. It’s not just about making things private. It’s about making the privacy mechanism itself understandable and verifiable. That’s a big step forward.

Tom: So stick around, because we’re going to break down how they actually pull this off, and why the results are so dramatic compared to the standard deep learning baselines.

Summary: Jane: Welcome back. So Tom, we’ve set the stage with the title, but let’s actually get into what this paper does. PrivateDFL, as they call it, combines decentralized federated learning with a noise accountant that tracks privacy loss in real time.

Tom: And that noise accountant is the star of the show. It’s not a post-hoc explanation tool. It’s built into the training loop. Every time a client receives the model, it knows exactly how much noise is already in there, and it calculates only the incremental noise needed to hit the privacy target.

Jane: So the privacy budget, which is that epsilon value, is respected across the entire network, but nobody is over-paying for it. The math they derive is pretty elegant. For the first client in the first round, they use one formula, and for everyone else, they use a unified formula that accounts for the client index and the round number.

Tom: And the key insight is that the total accumulated noise grows only logarithmically with the number of clients and rounds. In the old black-box approach, the noise grows super-exponentially because of that factorial term. That’s a massive difference.

Jane: Let me put that in plain terms. In their system, if you have a hundred clients and fifty rounds, the noise grows like the log of five thousand. In the old way, it grows like the log of five thousand *factorial*, which is astronomically larger.

Tom: And that’s why their accuracy numbers are so impressive. On MNIST, they hit ninety-five point seven four percent accuracy under IID conditions with a privacy budget of epsilon equals zero point four. That’s a very tight privacy guarantee, and they’re still getting near state-of-the-art accuracy.

Jane: And the comparisons are stark. They benchmarked against Vision Transformers, ResNet50, GoogLeNet, AlexNet, all trained with differential privacy. The best deep learning baseline on MNIST was ResNet50 at about seventy-nine point six percent. PrivateDFL beats that by over sixteen percentage points.

Tom: On ISOLET, which is a speech recognition dataset, the gap is even wilder. PrivateDFL gets eighty-eight point four five percent, while the Transformer baseline gets around five percent. That’s not a typo. Five percent. The deep models just collapse under the noise.

Jane: And on UCI-HAR, which is wearable sensor data for human activity recognition, PrivateDFL gets ninety-four point three percent while the best tabular baseline, a deep neural network, gets about seventy-nine point five percent. So across image, speech, and sensor data, the hyperdimensional approach just dominates.

Tom: And it’s not just accuracy. They also measured training time, inference latency, and energy consumption. PrivateDFL trains in about eight hundred twenty-one seconds on MNIST, while GoogLeNet takes over twenty-three thousand seconds. That’s a twenty-eight times speedup.

Jane: And inference latency is even more dramatic. PrivateDFL does inference in eleven milliseconds on MNIST, while the deep models take anywhere from seven hundred fifty-six to one thousand three hundred thirty-eight milliseconds. That’s up to a seventy-six times improvement.

Tom: And energy consumption is similarly lopsided. PrivateDFL uses zero point zero three megajoules on MNIST, while ResNet50 uses about four megajoules. That’s over a hundred times more energy for worse accuracy.

Jane: So the summary is pretty clear. This paper shows that you don’t need massive deep learning models to get strong privacy-preserving performance. A lightweight, interpretable model with smart noise management can beat them all.

Tom: And that’s a big deal for real-world deployment, especially on devices that don’t have the compute or battery to run a Transformer. We’ll talk about that next.

Improvements: Tom: So Jane, we’ve covered the results, but let’s talk about what this paper actually *improves* over the state of the art. The big one is the adaptive noise mechanism. Instead of blindly adding worst-case noise every round, PrivateDFL tracks the cumulative noise and adds only the incremental difference.

Jane: And that’s a fundamental improvement in how we think about privacy in decentralized systems. The old approach assumed every client had to protect against the worst-case scenario independently, which meant the noise kept piling up with no awareness of what came before.

Tom: Right, and the math in the paper is really clean. They show that the cumulative noise in PrivateDFL grows like the log of the number of samples, while the black-box approach grows like the log of a factorial. That factorial term is what kills the accuracy in the baselines.

Jane: And there’s another improvement that’s easy to miss. They’re using hyperdimensional computing, or HD, as the underlying model. HD represents data as high-dimensional vectors, like ten thousand-dimensional vectors, and classification is done by comparing similarities between vectors.

Tom: And the beauty of HD is that it’s naturally noise-tolerant. Because the representations are so high-dimensional, a little bit of Gaussian noise doesn’t destroy the signal. That’s why the accuracy holds up so well under differential privacy.

Jane: And HD is also incredibly lightweight. The operations are just addition, multiplication, and cosine similarity. No backpropagation, no gradients, no massive matrix multiplications. That’s why the training time and energy consumption are so low.

Tom: And they also made the whole thing interpretable. The HD model is essentially a set of class prototypes, which are just average hypervectors for each class. You can look at them and understand what the model has learned. That’s a level of transparency you don’t get with a deep neural network.

Jane: And the privacy accounting itself is explainable. The noise accountant tells you exactly how much noise has been added at every step and why. That makes it auditable, which is crucial for regulated industries like healthcare and finance.

Tom: And they tested this under both IID and non-IID conditions. In the non-IID case, where each client only has data from two classes, PrivateDFL still gets eighty-nine point three eight percent on MNIST. That’s only about six points lower than the IID case, which shows the framework is robust to data heterogeneity.

Jane: And they also did a sensitivity analysis on the hyperparameters. They found that hypervector dimensionality matters a lot for image data, but for speech and sensor data, the number of training samples per client matters more. That’s useful guidance for practitioners.

Tom: So the improvements here are threefold. You get better privacy-utility tradeoffs through adaptive noise, you get better efficiency through HD computing, and you get better transparency through the explainable accountant.

Jane: And that combination is what makes this paper stand out. It’s not just a theoretical contribution. It’s a practical framework that could actually be deployed on edge devices today.

Tom: And that’s exactly what we should talk about next, because the implications for real-world applications are huge.

Conclusion: Jane: Alright, we’re wrapping up our discussion of “Privacy-Preserving Decentralized Federated Learning via Explainable Adaptive Differential Privacy.” Let’s do a final recap of why this paper matters.

Tom: So the core contribution is PrivateDFL, a framework that makes decentralized federated learning both private and practical. It does this by tracking cumulative noise across clients and rounds, so each client only adds the minimum noise needed to satisfy the privacy budget.

Jane: And the results speak for themselves. On MNIST, ISOLET, and UCI-HAR, PrivateDFL beats differentially private Transformers and deep neural networks by massive margins, while using a fraction of the time, energy, and compute.

Tom: And the implications are broad. Think about healthcare, where hospitals can’t share patient data but want to train collaborative models. PrivateDFL lets them do that without a central server and with formal privacy guarantees.

Jane: Or think about industrial settings, like the authors’ home turf in mechanical engineering. Smart factories have proprietary sensor data from different machines. PrivateDFL could enable collaborative defect detection or predictive maintenance without exposing trade secrets.

Tom: And because it’s so lightweight, it can run on resource-constrained devices like IoT sensors, wearables, and edge gateways. You don’t need a data center to train a model. You can do it right on the devices.

Jane: The future work section is also exciting. They want to extend the noise accountant to handle adversarial participation, where some clients might try to poison the model. And they want to support heterogeneous privacy budgets, where different clients have different privacy requirements.

Tom: And dynamic topologies, where the network structure changes over time. That would make PrivateDFL even more flexible for real-world deployments.

Jane: So as we say goodbye to this paper, I think the takeaway is that privacy-preserving machine learning doesn’t have to mean sacrificing accuracy or efficiency. With the right model and the right noise management, you can have it all.

Tom: Absolutely, Jane. And I’m excited to see where this line of research goes. The combination of hyperdimensional computing and differential privacy is a powerful one, and this paper proves it works.

Jane: Thanks for joining us, everyone. We’ll be back with the next paper soon. Until then, keep learning and keep questioning.

Fardin Jalil Piran, Zhiling Chen, Yang Zhang, Qianyu Zhou, Jiong Tang, Farhad Imani

University of Connecticut

cs.CR, cs.AI

Submitted: 2026-08-16

Updated: 2026-08-18

Comments: 20 pages

Code: https://github.com/FardinJalilPiran/PrivateDFL

License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/

Importance score: 65/100

Key concepts

Federated Learning
This is a machine learning method where multiple devices train a shared model without sending their raw data to a central server. Clients communicate directly with each other, allowing the system to learn from distributed data while keeping sensitive information local.
Decentralized Federated Learning
This advanced form of FL removes the single point of failure by eliminating the central server. Clients operate in a peer-to-peer network, communicating directly to ensure that no single entity controls all the training data or model updates.
Differential Privacy
This technique involves adding carefully calibrated noise to shared model updates. The purpose is to ensure that no single person's data can be distinguished, providing a strong mathematical guarantee of privacy for the individuals in the dataset.
Hyperdimensional Computing (HD)
HD represents data using high-dimensional vectors. Classification is performed by comparing similarities between these vectors. This approach is noted for being extremely lightweight and naturally noise-tolerant, allowing it to perform well under differential privacy.

Terminology

Summary

Summary

This paper introduces PrivateDFL, a privacy-preserving decentralized federated learning framework that integrates HyperDimensional computing (HD) with a transparent, explainable differential privacy (DP) noise accountant. The motivation stems from the limitations of existing DP-enabled decentralized federated learning (DFL) methods, which operate as black-boxes that cannot track cumulative noise added across clients and rounds, forcing each participant to inject worst-case perturbations that severely degrade accuracy.

The framework addresses three core challenges: (1) DFL remains vulnerable to privacy attacks such as model inversion and membership inference because shared model updates can expose sensitive information; (2) standard DP-based DFL methods add a full dose of DP noise at every update without accounting for previously accumulated noise, leading to redundant noise injection and accelerated accuracy degradation; and (3) the absence of mechanisms for tracking cumulative noise renders privacy guarantees opaque and prevents auditing in safety-critical applications.

PrivateDFL's key innovation is an "eXplainable Artificial Intelligence (XAI)-guided noise accountant that records the cumulative noise injected by all previous clients and communication rounds, computes the required noise needed to satisfy the current DP budget after each local update, and injects only the incremental difference between these two quantities. This accountant is described as not a post-hoc explainer but a built-in transparency mechanism that makes DP behavior traceable, auditable, and mathematically verifiable across decentralized exchanges."

The framework operates with clients organized in a ring topology, sequentially updating a shared HD model using local data, enabling a fully serverless and communication-efficient training pipeline. The HD model provides structured, noise-tolerant high-dimensional representations that are naturally stable under noise and support efficient and robust updates on resource-constrained devices.

The paper provides formal mathematical foundations. The DP noise injection is governed by several theorems. For the first client in the first round, the noise is given by Theorem 2: Γ®11 ∼ N(0, (2D/ε2) ln(1.25N/δ0)). For subsequent clients in the first round, Theorem 3 specifies Γ®k ∼ N(0, (2D/ε2) ln(k/(k−1))). For the first client in subsequent rounds, Theorem 4 gives Γ®1r ∼ N(0, (2D/ε2) ln(K(r−1)+1)/(K(r−1))). For all other clients in subsequent rounds, Theorem 5 specifies Γ®kr ∼ N(0, (2D/ε2) ln(K(r−1)+k)/(K(r−1)+k−1)). The paper shows that the noise injection simplifies to a unified rule: the first client in the first round follows Theorem 2, while all other cases, including clients k ≥ 2 in the first round and all clients in subsequent rounds, follow Theorem 5.

A key theoretical contribution is the analysis of cumulative noise accumulation. Under PrivateDFL, the cumulative noise after any client k in round r is γ®rk ∼ N(0, (2D/ε2) ln(1.25(K(r−1)+k)N/δ0)), which exhibits only logarithmic growth in variance with respect to the number of clients and rounds. In contrast, the black-box case where noise cannot be tracked yields cumulative noise Ξ®rk ∼ N(0, (2D/ε2) ln(1.25N/δ0) + (2D/ε2) ln((K(r−1)+k)!)), which grows super-exponentially due to the factorial term (KR)!. The paper concludes that cumulative noise tracking is essential for preserving accuracy in decentralized differentially private learning.

The experimental evaluation covers three benchmark datasets: MNIST (image), ISOLET (speech), and UCI-HAR (wearable sensors), under both IID and non-IID partitions. The sensitivity analysis examines the effects of privacy budget ε, privacy-loss coefficient δ0, hypervector dimensionality D, number of clients K, and training samples per client.

Key sensitivity findings include: For MNIST under IID with 100 clients, accuracy ranges from 96.34% at ε=1 and δ0=10−3 to 75.16% at ε=0.001. Varying δ0 produces only marginal differences (approximately 0.56 percentage points when tightening from 10−3 to 10−18 at ε=0.1). Under non-IID conditions, the impact of privacy parameters becomes more pronounced for MNIST, with accuracy declining from 95.81% (IID) to 89.08% (non-IID) at ε=0.5 and δ0=10−6.

The analysis of hypervector dimensionality reveals dataset-dependent trends. For MNIST, accuracy is highly sensitive to hypervector dimensionality, increasing from 65.35% at D=50 to 91.86% at D=500 with 200 training samples per client. In contrast, ISOLET and UCI-HAR show that additional training samples contribute more effectively to performance than expanding hypervector dimensionality. For non-IID MNIST, larger dimensions mitigate noise effects, with accuracy reaching 90.95% at D=3000 after 200 rounds, though benefits saturate beyond this range.

The benchmark comparison evaluates PrivateDFL against state-of-the-art Transformer and deep learning models trained with DP-SGD and Rényi Differential Privacy (RDP) using Opacus. These baselines access the full dataset directly and therefore represent an upper bound on accuracy and latency without federated constraints. All comparisons use a fixed privacy budget of ε=0.4 and δ0=0.001.

Results show PrivateDFL consistently achieves the highest accuracy. For MNIST, PrivateDFL attains 95.74% (IID) and 89.38% (non-IID), compared to best baselines of 79.59% (ResNet50 DP-SGD) and 77.83% (ResNet50 RDP). For ISOLET, PrivateDFL achieves 88.45% (IID) and 86.66% (non-IID), while the best baseline (RNN) reaches only 25.59% with DP-SGD and 23.09% with RDP. For UCI-HAR, PrivateDFL achieves 94.30% (IID) and 92.33% (non-IID), compared to 79.47% (DNN DP-SGD) and 78.72% (DNN RDP).

The runtime analysis shows substantial efficiency gains. For MNIST, PrivateDFL completes training in 820.97 seconds (IID) and 730.81 seconds (non-IID), while GoogLeNet requires 23127.31 seconds with DP-SGD. Inference latency for PrivateDFL is 11.16 milliseconds, compared to 756–1338 milliseconds for deep models. For ISOLET, PrivateDFL trains in 311.71 seconds (IID) and 79.60 seconds (non-IID), with inference latency of 1.98 milliseconds versus 83–216 milliseconds for baselines. For UCI-HAR, PrivateDFL trains in 124.85 seconds (IID) and 92.95 seconds (non-IID), with inference latency of 4.19 milliseconds versus 68–471 milliseconds for baselines.

Energy consumption analysis shows PrivateDFL consumes only 0.03 MJ for MNIST (both IID and non-IID), compared to 0.33 MJ for Vision Transformer, 1.29–1.33 MJ for GoogLeNet, 3.6 MJ for AlexNet, and 3.97–3.99 MJ for ResNet50. For ISOLET, PrivateDFL consumes 12.32 kJ (IID) and 3.43 kJ (non-IID), versus 65–67 kJ for RNN, 124–130 kJ for Transformer, 330 kJ for CNN, and over 450 kJ for TCN. For UCI-HAR, PrivateDFL consumes 4.96 kJ (IID) and 3.50 kJ (non-IID), versus 18–21 kJ for TabNet, 20–34 kJ for DNN/DCN, and approximately 248 kJ for TabTransformer.

The paper summarizes the accuracy improvements: improving accuracy by up to 24.4% on MNIST, over 80% on ISOLET, and 14.7% on UCI-HAR, while reducing inference latency by up to 76× and energy consumption by up to 36×. The paper notes that "Relative to Transformer models, the advantage reaches as high as 83% on ISOLET and about 31% on MNIST. Relative to deep neural networks, the advantage reaches 63% on ISOLET and 16% on MNIST, while on UCI-HAR PrivateDFL exceeds the strongest tabular baseline by about 15%."

The paper identifies several limitations and future directions: extending noise accounting to asynchronous schedules, dynamic topologies, and intermittent participation; developing adaptive privacy budgets that reflect local data difficulty or sensitivity while preserving global guarantees; studying robustness to adversarial behavior requires deeper study, including targeted data poisoning, backdoor insertion, and strong inference attacks under heterogeneous participation; and integrating secure aggregation, lightweight HE, or verifiable update mechanisms may further strengthen the protocol while maintaining its computational efficiency.

The paper concludes that "PrivateDFL shows that interpretable hyperdimensional representations, decentralized learning, and explainable DP can be combined to deliver high accuracy, strong privacy, low latency, and low energy consumption. These results support the use of PrivateDFL as a practical and scalable solution for trustworthy privacy-preserving learning in distributed and sensitive environments." The work was supported by the National Science Foundation under grant number 2434519, and the code is openly available at https://github.com/FardinJalilPiran/PrivateDFL.git.

Improvements for AI systems

Based on the paper, here are the specific improvements I can make to AI systems and what the improved system can do:

1. Replace black-box DP noise injection with an XAI-guided noise accountant

  • Current limitation: Most DP-enabled federated learning systems inject worst-case noise at every update because they cannot track cumulative noise, causing severe accuracy degradation.

  • Improvement: I will implement a transparent noise accountant that explicitly tracks cumulative perturbations across all clients and rounds. Each client computes only the incremental noise needed to satisfy its (ε, δ) budget, rather than full worst-case noise.

  • Result: Noise variance grows logarithmically with clients/rounds (σ2 ∝ ln(KR)) instead of super-exponentially (σ2 ∝ ln((KR)!)), preserving model utility.

2. Integrate Hyperdimensional Computing (HD) as the backbone model

  • Current limitation: Deep neural networks (Transformers, CNNs, RNNs) are highly sensitive to DP noise and require massive compute, making them impractical for resource-constrained decentralized clients.

  • Improvement: I will use HD's high-dimensional distributed representations (class hypervectors) that are naturally noise-tolerant and support lightweight operations (encoding, bundling, similarity search). This replaces heavy backpropagation with simple vector arithmetic.

  • Result: Up to 76× lower inference latency, 36× lower energy consumption, and 80%+ accuracy improvements on speech/sensor tasks compared to DP-trained deep models.

3. Implement adaptive, mathematically-verified noise scheduling

  • Current limitation: Existing DP-DFL methods use fixed noise levels without formal derivation for each client/round, leading to either over-perturbation (poor accuracy) or under-perturbation (privacy leaks).

  • Improvement: I will use the paper's Theorems 2–5 to compute exact Gaussian noise variance for every client k in round r, based on the number of aggregated samples and the privacy budget. This ensures formal (ε, δ) guarantees with minimal noise.

  • Result: Guaranteed privacy with accuracy improvements of up to 24.4% (MNIST), 80% (ISOLET), and 14.7% (UCI-HAR) over centralized DP-SGD/RDP baselines.

4. Enable fully serverless, ring-topology training

  • Current limitation: Centralized FL has a single point of failure and is vulnerable to server-side attacks.

  • Improvement: I will implement sequential peer-to-peer model updates in a ring topology, where each client receives, updates, and forwards the HD model without a central aggregator. The noise accountant works correctly in this decentralized setting.

  • Result: Enhanced robustness, fault tolerance, and scalability for IoT/sensor networks, with no reliance on a trusted coordinator.

  • Achieve high accuracy under strict privacy: Maintain 95.74% accuracy on MNIST, 88.45% on ISOLET, and 94.30% on UCI-HAR with ε=0.4, δ0=0.001—even when deep learning baselines collapse to <10% accuracy.

  • Operate on resource-constrained devices: Run training and inference on edge devices (e.g., Raspberry Pi, microcontrollers) with millisecond-level latency and kilojoule-level energy consumption, making real-time privacy-preserving pattern recognition feasible.

  • Provide auditable privacy guarantees: Allow any participant to verify the exact cumulative noise in the model at any point, enabling transparent compliance with regulations (HIPAA, GDPR) in healthcare, finance, and industrial sensing.

  • Handle non-IID data distributions: Maintain strong performance (89–92% accuracy) even when clients hold only 2 classes each, unlike DP-trained deep models that fail catastrophically.

  • Scale to hundreds/thousands of clients: Keep accuracy stable (standard deviation <7.4%) as client count grows from 10 to 1000, with noise growing only logarithmically.

  • Support real-time monitoring: Enable privacy-preserving defect detection, anomaly monitoring, and predictive maintenance in manufacturing, where data cannot be centralized due to proprietary or regulatory constraints.

Sources

Related papers