Securing Model Weights Against Eavesdropping Adversaries in Federated Learning Using Quantization

Kushal Chakrabarti, Dipankar Maity
Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, PMLR 300:3970-3978, 2026.

Abstract

While security research in Federated Learning (FL) has predominantly focused on protecting client data, the \emph{confidentiality of the model parameters} themselves represents a critical and underexplored vulnerability. This work addresses model reconstruction attacks by passive eavesdroppers, a threat present in common update strategies like transmitting full models or model increments. To our knowledge, we are the first to repurpose dynamic uniform quantization as a dedicated defense for model confidentiality. Our lightweight, architecture-agnostic approach combines low-bit quantization with an adaptive clipping rule to thwart reconstruction attacks, even under warm adversary initialization. We provide theoretical guarantees establishing that our defense offers persistent, non-zero protection in both protocols. Across extensive experiments on CIFAR-10 and CIFAR-100, with up to 1000 clients in heterogeneous settings, our method reduces the adversary’s test accuracy to near-random levels while maintaining global accuracy within 4% of the unquantized baseline. Our findings establish that repurposing quantization is a simple yet highly effective strategy for securing the largely overlooked area of model confidentiality in FL.

Cite this Paper


BibTeX
@InProceedings{pmlr-v300-chakrabarti26a, title = { Securing Model Weights Against Eavesdropping Adversaries in Federated Learning Using Quantization }, author = {Chakrabarti, Kushal and Maity, Dipankar}, booktitle = {Proceedings of The 29th International Conference on Artificial Intelligence and Statistics}, pages = {3970--3978}, year = {2026}, editor = {Khan, Emtiyaz and Li, Yingzhen and Solin, Arno and Ramdas, Aaditya}, volume = {300}, series = {Proceedings of Machine Learning Research}, month = {02--05 May}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v300/main/assets/chakrabarti26a/chakrabarti26a.pdf}, url = {https://proceedings.mlr.press/v300/chakrabarti26a.html}, abstract = { While security research in Federated Learning (FL) has predominantly focused on protecting client data, the \emph{confidentiality of the model parameters} themselves represents a critical and underexplored vulnerability. This work addresses model reconstruction attacks by passive eavesdroppers, a threat present in common update strategies like transmitting full models or model increments. To our knowledge, we are the first to repurpose dynamic uniform quantization as a dedicated defense for model confidentiality. Our lightweight, architecture-agnostic approach combines low-bit quantization with an adaptive clipping rule to thwart reconstruction attacks, even under warm adversary initialization. We provide theoretical guarantees establishing that our defense offers persistent, non-zero protection in both protocols. Across extensive experiments on CIFAR-10 and CIFAR-100, with up to 1000 clients in heterogeneous settings, our method reduces the adversary’s test accuracy to near-random levels while maintaining global accuracy within 4% of the unquantized baseline. Our findings establish that repurposing quantization is a simple yet highly effective strategy for securing the largely overlooked area of model confidentiality in FL. } }
Endnote
%0 Conference Paper %T Securing Model Weights Against Eavesdropping Adversaries in Federated Learning Using Quantization %A Kushal Chakrabarti %A Dipankar Maity %B Proceedings of The 29th International Conference on Artificial Intelligence and Statistics %C Proceedings of Machine Learning Research %D 2026 %E Emtiyaz Khan %E Yingzhen Li %E Arno Solin %E Aaditya Ramdas %F pmlr-v300-chakrabarti26a %I PMLR %P 3970--3978 %U https://proceedings.mlr.press/v300/chakrabarti26a.html %V 300 %X While security research in Federated Learning (FL) has predominantly focused on protecting client data, the \emph{confidentiality of the model parameters} themselves represents a critical and underexplored vulnerability. This work addresses model reconstruction attacks by passive eavesdroppers, a threat present in common update strategies like transmitting full models or model increments. To our knowledge, we are the first to repurpose dynamic uniform quantization as a dedicated defense for model confidentiality. Our lightweight, architecture-agnostic approach combines low-bit quantization with an adaptive clipping rule to thwart reconstruction attacks, even under warm adversary initialization. We provide theoretical guarantees establishing that our defense offers persistent, non-zero protection in both protocols. Across extensive experiments on CIFAR-10 and CIFAR-100, with up to 1000 clients in heterogeneous settings, our method reduces the adversary’s test accuracy to near-random levels while maintaining global accuracy within 4% of the unquantized baseline. Our findings establish that repurposing quantization is a simple yet highly effective strategy for securing the largely overlooked area of model confidentiality in FL.
APA
Chakrabarti, K. & Maity, D.. (2026). Securing Model Weights Against Eavesdropping Adversaries in Federated Learning Using Quantization . Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, in Proceedings of Machine Learning Research 300:3970-3978 Available from https://proceedings.mlr.press/v300/chakrabarti26a.html.

Related Material