Formalisation of Security for Federated Learning with DP and Attacker Advantage in IIIf for Satellite Swarms -- Extended Version

📅 2025-12-06
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Federated learning (FL) in distributed systems such as satellite constellations is vulnerable to gradient leakage (DLG) attacks, yet existing differential privacy (DP)-based defenses lack formal security guarantees. Method: We present the first rigorous formalization—within Isabelle’s IIIf framework—of the relationship between DP parameters and adversary advantage in FL, directly linking privacy budgets to quantifiable attack success probabilities. Our model captures dynamic distributed FL protocols, gradient update mechanisms, and adversarial capabilities, enabling machine-checked security verification of DLG defenses. Contribution: This work establishes a provably secure theoretical foundation for FL, supporting automated, machine-assisted verification. We quantitatively evaluate defense strength in satellite constellation scenarios, significantly strengthening theoretical guarantees against gradient inversion attacks. (149 words)

Technology Category

Machine Learning: Distributed Machine Learning & Federated LearningComputer Vision: Adversarial Attacks & RobustnessMultiagent Systems: Adversarial Agents

Application Category

Security and Privacy: Large-scale security measurementsUser Modeling, Personalization and Recommendation: Attacks and countermeasures in recommendation systemsSystems and Infrastructure for Web, Mobile and WoT: Federated Web and WoT systems, including distributed, federated and edge-based data processing
📝 Abstract
In distributed applications, like swarms of satellites, machine learning can be efficiently applied even on small devices by using Federated Learning (FL). This allows to reduce the learning complexity by transmitting only updates to the general model in the server in the form of differences in stochastic gradient descent. FL naturally supports differential privacy but new attacks, so called Data Leakage from Gradient (DLG) have been discovered recently. There has been work on defenses against DLG but there is a lack of foundation and rigorous evaluation of their security. In the current work, we extend existing work on a formal notion of Differential Privacy for Federated Learning distributed dynamic systems and relate it to the notion of the attacker advantage. This formalisation is carried out within the Isabelle Insider and Infrastructure framework (IIIf) allowing the machine supported verification of theory and applications within the proof assistant Isabelle. Satellite swarm systems are used as a motivating use case but also as a validation case study.
Problem

Research questions and friction points this paper is trying to address.

Formalizes security for Federated Learning with Differential Privacy and attacker advantage.
Addresses Data Leakage from Gradient attacks in distributed systems like satellite swarms.
Provides machine-verified formalization using the Isabelle IIIf framework for rigorous evaluation.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Formalizing DP security for federated learning systems
Integrating attacker advantage into DP analysis
Verifying security with Isabelle proof assistant