[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120683-en":3,"doc-seo-120683-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120683,1099513958762,"Logic","https://ap-avatar.wpscdn.com/avatar/1000023916a998db790?x-image-process=image/resize,m_fixed,w_180,h_180&k=1784791008015729253",8,"Research & Report","On the (In)security of Peer-to-Peer Decentralized Machine Learning - Privacy analysis and attack surface findings","First in-depth privacy analysis of decentralized learning, a collaborative machine learning framework designed to address federated learning limitations. The work introduces novel passive and active adversarial attacks and shows that decentralized learning provides no security advantage over federated learning. Decentralization enlarges the attack surface: attackers can perform gradient inversion, infer sample membership, and even gain full control over honest users’ local models. Achieving privacy-preserving decentralized setups requires fully connected networks, erasing practical efficiency gains.","On the (In)security of  \nPeer-to-Peer Decentralized Machine Learning  \nDario Pasquini  \nSPRING Lab; EPFL, Switzerland dario.pasquini@epﬂ.ch  \nMathilde Raynal  \nSPRING Lab; EPFL, Switzerland mathilde.raynal@epﬂ.ch  \nCarmela Troncoso  \nSPRING Lab; EPFL, Switzerland carmela.troncoso@epﬂ.ch  \narXiv :2205 .08443v2 [ cs .CR] 27 Apr 2023  \nAbstract—In this work, we carry out the ﬁrst, in-depth, privacy analysis of Decentralized Learning—a collaborative machine learning framework aimed at addressing the main limitations of federated learning. We introduce a suite of novel attacks for both passive and active decentralized adversaries. We demonstrate that, contrary to what is claimed by decentralized learning proposers, decentralized learning does not offer any security advantage over federated learning. Rather, it increases the attack surface enabling any user in the system to perform privacy attacks such as gradient inversion, and even gain full control over honest users' local model. We also show that, given the state of the art in protections, privacy-preserving conﬁgurations of decentralized learning require fully connected networks, losing any practical advantage over the federated setup and therefore completely defeating the objective of the decentralized approach.  \nIndex Terms—Collaborative Machine Learning, Privacy attacks, Peer-to-Peer systems  \n1. Introduction  \nCollaborative machine learning is gaining traction asa way to train machine learning models while respecting the privacy of users' local training dataset [40] . There are two main approaches to collaborative machine learning: federated learning [40] and decentralized learning [36] .  \nIn federated learning, the iterative learning process is orchestrated by a central parameter server. This server intermediates communication in-between users and maintains the global state of the system. Such central component can become a communication bottleneck as the number of users grows, and, due to its full control on the learning process, can perform a number of security and privacy attacks on users [3], [15], [50], [64], [16], [79] .  \nDecentralized machine learning, also known as fullydecentralized machine learning, peer-to-peer machine learning, or gossip learning, aims at addressing these issues by eliminating the central server. Instead, the learning takes place via peer-to-peer communication, see Figure 1 . Proponents of decentralized learning argue that decentralization:  \n1. This paper appears in the proceedings of the 44nd IEEE Symposium on Security and Privacy S&P 2023 .  \n(a) reduces bandwidth consumption,(b) provides users with control on who they communicate with, and (c) increases privacy of users in the system by eliminating the central server. A large body of theoretical studies, empirical evaluations, and model extensions attest to (a) and (b) [7], [23],[25], [30], [31], [32], [34], [35], [38], [49], [51], [52], [61],[36], [66], [72], [73], [62], [20] . However, these works do not assess (c) . Either they state that decentralized learning offers a higher level of privacy compared to the centralized approach without any evidence [7], [61], [20], [39], [58], or simply do not provide any privacy argument [25], [32],[34], [35], [36], [66], [72], [62], [11] .  \nIn this work, we thoroughly evaluate the privacy offered by decentralized learning, against both passive and active adversaries. We propose novel attacks that demonstrate that in a decentralized setting: (1) A passive adversarial user can successfully (i) infer membership of samples with better accuracy than in the federated setting and (ii) perform reconstruction attacks on the training set of arbitrary honest users. (2) An active adversarial user can (i) inﬂuence the update process of honest users in arbitrary ways and (ii) and perform effective privacy attacks such active gradient inversion [64], [3] .  \nWe show that these attacks are possible because decentralization increases the inference power of users,","cbCailmPANEFTRDa","https://ap.wps.com/l/cbCailmPANEFTRDa","pdf",1805158,1,19,"English","en",105,"# Introduction\n## Federated vs decentralized learning\n## Threat model and novel attacks\n# Privacy evaluation and findings\n## Passive and active adversaries\n## Mitigation conflicts and feasibility","[{\"question\":\"What is the main objective of the study on decentralized learning privacy?\",\"answer\":\"The study performs the first in-depth privacy analysis of decentralized learning and compares its privacy to federated learning against both passive and active adversaries.\"},{\"question\":\"What attacks are introduced for passive and active decentralized adversaries?\",\"answer\":\"Passive adversaries can infer sample membership and reconstruct training data of honest users. Active adversaries can arbitrarily influence update processes and perform effective privacy attacks such as active gradient inversion.\"},{\"question\":\"Why does decentralized learning not provide a security advantage over federated learning?\",\"answer\":\"Decentralization increases users’ inference power and their influence on others’ status, making adversarial users as capable as the parameter server. Mitigations also conflict, and comparable privacy requires fully connected networks that eliminate decentralization’s practical advantage.\"}]","On the (In)security of Peer-to-Peer Decentralized Machine Learning - Privacy analysis and attack surface findings | PDF",1785731466,48,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"on-the-insecurity-of-peer-to-peer-decentralized-machine-learning-privacy-analysis-and-attack-surface-findings","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/on-the-insecurity-of-peer-to-peer-decentralized-machine-learning-privacy-analysis-and-attack-surface-findings/120683/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04","2026-08-03",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is the main objective of the study on decentralized learning privacy?","Question",{"text":76,"@type":77},"The study performs the first in-depth privacy analysis of decentralized learning and compares its privacy to federated learning against both passive and active adversaries.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What attacks are introduced for passive and active decentralized adversaries?",{"text":81,"@type":77},"Passive adversaries can infer sample membership and reconstruct training data of honest users. Active adversaries can arbitrarily influence update processes and perform effective privacy attacks such as active gradient inversion.",{"name":83,"@type":74,"acceptedAnswer":84},"Why does decentralized learning not provide a security advantage over federated learning?",{"text":85,"@type":77},"Decentralization increases users’ inference power and their influence on others’ status, making adversarial users as capable as the parameter server. Mitigations also conflict, and comparable privacy requires fully connected networks that eliminate decentralization’s practical advantage.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":46,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},"General","general"]