[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84504-en":3,"doc-seo-84504-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},84504,549758146520,"Patrick","https://ap-avatar.wpscdn.com/avatar/80002397d8c0411e94?_k=1775819394049821470",8,"Research & Report","IntraShuffler: A Privacy Preserving Framework for Heterogeneous DP Federated Learning","Heterogeneous Differential Privacy (HDP) in Federated Learning (FL) lets each client choose an individual privacy budget (εi), and many systems use ε-aware server aggregation to re-weight updates for better utility. Yet gradients from non-IID data keep client-specific structural patterns, and ε-aware aggregation adds signals that an honest-but-curious server can exploit. The work presents a privacy inference attack using gradient denoising and surrogate modeling to infer distributional attributes and link updates across rounds. It then proposes IntraShuffler, a privacy-aware shuffling middleware that buckets privacy-compatible clients and performs parameter-level shuffling to break persistent structure. Experiments on four datasets reduce gradient recoverability by over 60% and lower surrogate inference accuracy from 0.78 to 0.33 while preserving comparable model utility under multiple aggregation rules.","arXiv :2606 .02563v2 [ cs .LG] 13 Jul 2026  \nIntraShuffler: A Privacy Preserving Framework for Heterogeneous DP Federated Learning  \nFarhin Farhad Riya 1 , Olivera Kotevska2 , and Jinyuan Stella Sun 1  \n1 University of Tennessee, Knoxville, USA  \n2 Oak Ridge National Laboratory, USA  \n[friya@vols.utk.edu](friya@vols.utk.edu) ; [kotevskao@ornl.gov](kotevskao@ornl.gov) ; [jysun@utk.edu](jysun@utk.edu)  \nAbstract. Heterogeneous Differential Privacy (HDP) in Federated Learning (FL) allows clients to select individual privacy budgets (εi ) according to institutional policies and data sensitivity. In practice, many HDP-FL systems employ ε-aware server aggregation to improve model utility by re-weighting client updates according to their declared privacy budgets.  \nHowever, gradient updates in FL retain structural patterns induced by non-independent and identically-distributed (non-IID) data, and these additional signals exposed by ε-aware aggregation create new opportunities for inference by an honest-but-curious server. In this work, we first show that a server equipped with gradient denoising and surrogate modeling can mount a Privacy Inference Attack that infers distributional attributes of clients and links updates from the same client across training rounds, measured via surrogate inference accuracy and linkage success, under realistic knowledge constraints.  \nThe Shuffle-Model has been widely studied as a defense against such inference risks by anonymizing update sources, but it is fundamentally incompatible with HDP-FL ε-aware aggregation. To address this challenge, we propose IntraShuffler, a middleware defense framework designed for HDP-FL systems. IntraShuffler introduces a privacy-aware shuffling mechanism that groups clients into privacy-compatible buckets and performs parameter-level shuffling within each bucket to disrupt persistent gradient structure while preserving ε-aware aggregation. Experiments across four different datasets show that IntraShuffler reduces gradient recoverability by over 60% and decreases surrogate inference accuracy from 0.78 to 0.33 while maintaining comparable model utility across multiple FL aggregation rules.  \n1 Introduction  \nFederated Learning (FL) enables collaborative model training across distributed clients without sharing raw data, where clients compute local updates that are aggregated by a central server [1, 2] . Despite this decentralized design, prior work shows that shared updates can still leak sensitive information about client data and behavior [3, 4] . Differential Privacy (DP) is widely adopted to mitigate such risks by adding noise to client updates [5, 6] . In practice, clients often have heterogeneous privacy requirements, motivating Heterogeneous Differential Privacy (HDP), where each client selects an individual privacy budget εi [7, 8] . To ensure  \nconvergence under heterogeneous noise, many HDP-FL systems adopt ε-aware aggregation that re-weights updates based on their declared privacy budgets. However, privacy risks persist as gradient updates retain structural patterns induced by non-IID data, and ε-aware aggregation introduces additional signal that can be exploited to enable inference. This raises an important question: Can an honest-but-curious server infer client participation or distributional attributes with these signals even when LDP is applied? For example, a client with a large privacy budget (ε = 8) produces consistently low-noise updates with similar directionality across rounds, enabling linkage even under shuffling. We identify that the root cause of privacy leakage in HDP-FL is not insufficient noise or lack of anonymization, but the persistence of client-specific gradient structure under ε-aware aggregation.  \nIn this work, we demonstrate that such inference is indeed possible in HDPFL systems. Leveraging two well-established analysis capabilities, gradient denoising techniques that partially recover gradient directionality and surrogate modeling t","cbCaial4FFMxKJBv","https://ap.wps.com/l/cbCaial4FFMxKJBv","pdf",4058134,1,20,"English","en",105,"# Abstract\n# 1 Introduction\n## Motivation: HDP-FL and ε-aware aggregation\n## Privacy inference risk from persistent non-IID gradient structure\n## Shuffle-model limitations in HDP-FL\n## Proposed solution: IntraShuffler and bucketing parameter-level shuffling","[{\"question\":\"What privacy risk does ε-aware aggregation introduce in heterogeneous DP federated learning?\",\"answer\":\"It preserves client-specific structural patterns from non-IID data and adds signals that an honest-but-curious server can use for inference and cross-round linkage.\"},{\"question\":\"How does the proposed privacy inference attack work?\",\"answer\":\"It combines gradient denoising to recover partial gradient directionality with surrogate modeling to infer distributional attributes and identify update sources under realistic knowledge constraints.\"},{\"question\":\"Why are existing shuffle-model defenses insufficient for HDP-FL with ε-aware aggregation?\",\"answer\":\"Message-level anonymization conflicts with the need to associate each update with its privacy tier, so removing identity-linked signals can also remove aggregation weights required for correct learning.\"}]",1784196149,50,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"intrashuffler-a-privacy-preserving-framework-for-heterogeneous-dp-federated-learning","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/intrashuffler-a-privacy-preserving-framework-for-heterogeneous-dp-federated-learning/84504/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What privacy risk does ε-aware aggregation introduce in heterogeneous DP federated learning?","Question",{"text":75,"@type":76},"It preserves client-specific structural patterns from non-IID data and adds signals that an honest-but-curious server can use for inference and cross-round linkage.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the proposed privacy inference attack work?",{"text":80,"@type":76},"It combines gradient denoising to recover partial gradient directionality with surrogate modeling to infer distributional attributes and identify update sources under realistic knowledge constraints.",{"name":82,"@type":73,"acceptedAnswer":83},"Why are existing shuffle-model defenses insufficient for HDP-FL with ε-aware aggregation?",{"text":84,"@type":76},"Message-level anonymization conflicts with the need to associate each update with its privacy tier, so removing identity-linked signals can also remove aggregation weights required for correct learning.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,114,119,122,126,129,133],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":28,"slug":113},6,"Technology","technology",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":45,"category_name":124,"show_sort_weight":21,"slug":125},9,"Religion & Spirituality","religion-spirituality",{"id":21,"doc_module":4,"doc_module_name":45,"category_name":127,"show_sort_weight":21,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":45,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":45,"category_name":135,"show_sort_weight":106,"slug":136},19,"General","general"]