An Adaptive Differential Privacy Framework for Secure Cloud Edge Federated Learning using Gradient Norm Dynamics
Abstract
The concept of Federated Learning (FL) allows training models in a decentralized way without distributing raw data but, nonetheless, the gradients are vulnerable to privacy attacks that include gradient inversion, reconstruction, and membership inference. Differential Privacy (DP) is broadly used to address these risks, but fixed noise injection can commonly worsen convergence, especially in heterogeneous edge cloud systems. To overcome this drawback, we introduce FADP-FL, a Gradient-Norm-Driven Adaptive Differential Privacy algorithm, which adjusts the Gaussian noise per client dynamically depending on the sensitivity of the local updates. The proposed framework dynamically adjusts Gaussian noise according to client gradient sensitivity, thereby improving the privacy-utility tradeoff while maintaining model performance. F-ADP-FL was implemented in a Google Colab-based federated simulation environment and evaluated against FedAvg and Fixed-Noise DP-FL using the MNIST dataset. It is shown experimentally that F-ADP-FL is more stable in convergence and more accurate than fixed-noise DP, and has significant privacy guarantees. The proposed adaptive DP mechanism to privacy preserving FL is described in terms of its full methodology, algorithm design, implementation workflow and performance analysis.