Home/Glossary/6G Glossary/Differential Privacy in FL
6G • Security

Differential Privacy in FL

Epsilon-Calibrated Noise Injection in AI Models

Adding calibrated mathematical noise to federated learning model updates so that individual user data cannot be reverse-engineered from global models.

Technical Explanation

When thousands of smartphones collaborate to train a predictive text or channel estimation model via federated learning, sophisticated attackers can perform 'membership inference' or model inversion attacks to reconstruct private user training samples. Differential Privacy injects mathematically calibrated Laplacian or Gaussian noise into local gradient vectors before transmission. This bounds privacy leakage by an epsilon factor, mathematically guaranteeing that no individual user's data can be extracted from the model.

Key Functions

  • Injecting calibrated mathematical noise into local gradients to prevent model inversion attacks
  • Provable, quantifiable privacy guarantees bounded by mathematical epsilon parameters
  • Preventing reconstruction of private user text, browsing habits, or health vitals from AI models
  • Balancing privacy guarantees against global model training accuracy and convergence speed
  • Standardized privacy protection for 6G NWDAF distributed analytics models
Specifications
NIST SP 800-226 (Differential Privacy Guidelines), 3GPP Rel-19 NWDAF Privacy
Interfaces
DiffPrivacy-CoreNoise-Inject-Bus

Related 6G Concepts

Want to memorize 6G concepts like this one?
Study it with SuperMemo SM-2 spaced repetition flashcards.
Practice 6G Flashcards