[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125366-en":3,"doc-seo-125366-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},125366,13056703019662,"Evangeline","https://ap-avatar.wpscdn.com/avatar/be000253a8e92610077?_k=1778726343310543188",8,"Research & Report","PriPrune - Quantifying and Preserving Privacy in Pruned Federated Learning","Model pruning reduces the size and complexity of federated learning (FL) networks, and is commonly expected to strengthen privacy by making local models coarser. Prior work lacked a clear characterization and joint optimization of privacy versus utility. This paper first quantifies privacy from pruning using information-theoretic upper bounds on leakage in pruned FL, validated under state-of-the-art attacks across pruning schemes. It then proposes PriPrune, a privacy-aware defense-masking pruning method with pseudo-pruning to jointly optimize privacy and accuracy.","PriPrune: Quantifying and Preserving Privacy in Pruned Federated Learning  \nTIANYUE CHU∗ , IMDEA Networks Institute and Universidad Carlos III de Madrid, Spain  \nMENGWEI YANG∗ , University of California, Irvine, USA NIKOLAOS LAOUTARIS, IMDEA Networks Institute, Spain ATHINA MARKOPOULOU, University of California, Irvine, USA  \nModel pruning has been proposed as a technique for reducing the size and complexity of Federated learning (FL) models. By making local models coarser, pruning is intuitively expected to improve protection against privacy attacks. However, the level of this expected privacy protection has not been previously characterized, or optimized jointly with utility. In this paper, we first characterize the privacy offered by pruning. We establish information-theoretic upper bounds on the information leakage from pruned FL and we experimentally validate them under state-of-the-art privacy attacks across different FL pruning schemes. Second, we introduce PriPrune– a privacy-aware algorithm for pruning in FL. PriPrune uses defense pruning masks, which can be applied locally after any pruning algorithm, and adapts the defense pruning rate to jointly optimize privacy and accuracy. Another key idea in the design of PriPrune is pseudo-pruning: it undergoes defense pruning within the local model and only sends the pruned model to the server; while the weights pruned out by defense mask are withheld locally for future local training rather than being removed. We show that PriPrune significantly improves the privacy-accuracy tradeoff compared to state-of-the-art pruned FL schemes. For example, on the FEMNIST dataset, PriPrune improves the privacy of PruneFL by 45.5% without reducing accuracy.  \nCCS Concepts: • Do Not Use This Code → Generate the Correct Terms for Your Paper; Generate the Correct Terms for Your Paper; Generate the Correct Terms for Your Paper; Generate the Correct Terms for Your Paper.  \nAdditional Key Words and Phrases: Federated learning, Privacy, Model pruning  \nACM Reference Format:  \nTianyue Chu, Mengwei Yang, Nikolaos Laoutaris, and Athina Markopoulou. 2018. PriPrune: Quantifying and Preserving Privacy in Pruned Federated Learning. J. ACM 37, 4, Article 111 (August 2018), 32 pages. [https://doi.org/XXXXXXX.XXXXXXX](https://doi.org/XXXXXXX.XXXXXXX)  \n1 INTRODUCTION  \nFederated Learning (FL) has emerged as the predominant paradigm for distributed machine learning across a multitude of user devices [18, 26] . It is known to have several benefits in terms of reducing the communication, computation and storage costs for the users, training better global models, and raising the bar for privacy by not sharing the local data. FL allows users to train models locally on their (user) devices without revealing their local data but instead collaborate by sharing only model updates that can be combined to build a global model through a central server. A typical FL scenario  \n∗ Both authors contributed equally to the paper.  \nAuthors’ addresses: Tianyue Chu, IMDEA Networks Institute and Universidad Carlos III de Madrid, Madrid, Spain, [tianyue.chu@imdea.org](tianyue.chu@imdea.org); Mengwei Yang, University of California, Irvine, Irvine, USA, [mengwey@uci.edu](mengwey@uci.edu); Nikolaos Laoutaris, IMDEA Networks Institute, Madrid, Spain, nikolaos.laoutaris@ [imdea.org](imdea.org); Athina Markopoulou, University of California, Irvine, Irvine, USA, [athina@uci.edu](athina@uci.edu).  \nPermission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, [requires prior specific permission and/or a fee. Reques","cbCaiesfxzYpjaOc","https://ap.wps.com/l/cbCaiesfxzYpjaOc","pdf",5386892,1,32,"English","en",105,"# Introduction\n## Federated learning and model pruning\n## Privacy characterization of pruned FL\n## PriPrune: privacy-aware defense pruning","[{\"question\":\"Why does model pruning relate to privacy in federated learning?\",\"answer\":\"Pruning makes local FL models coarser by removing parameters, which can reduce the information available for privacy attacks such as reconstruction or gradient inversion from shared updates.\"},{\"question\":\"How does the paper quantify privacy for pruned federated learning?\",\"answer\":\"It establishes information-theoretic upper bounds on information leakage from pruned FL and experimentally validates the bounds using state-of-the-art privacy attacks across different pruning schemes.\"},{\"question\":\"What is PriPrune and how does it optimize privacy and accuracy?\",\"answer\":\"PriPrune applies defense pruning masks after any pruning algorithm and adapts the defense pruning rate to jointly optimize privacy and accuracy. It also uses pseudo-pruning: locally prune for defense while withholding defense-masked weights for future local training instead of deleting them.\"}]","PriPrune - Quantifying and Preserving Privacy in Pruned Federated Learning | PDF",1785898446,81,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"priprune-quantifying-and-preserving-privacy-in-pruned-federated-learning","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/priprune-quantifying-and-preserving-privacy-in-pruned-federated-learning/125366/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why does model pruning relate to privacy in federated learning?","Question",{"text":75,"@type":76},"Pruning makes local FL models coarser by removing parameters, which can reduce the information available for privacy attacks such as reconstruction or gradient inversion from shared updates.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the paper quantify privacy for pruned federated learning?",{"text":80,"@type":76},"It establishes information-theoretic upper bounds on information leakage from pruned FL and experimentally validates the bounds using state-of-the-art privacy attacks across different pruning schemes.",{"name":82,"@type":73,"acceptedAnswer":83},"What is PriPrune and how does it optimize privacy and accuracy?",{"text":84,"@type":76},"PriPrune applies defense pruning masks after any pruning algorithm and adapts the defense pruning rate to jointly optimize privacy and accuracy. It also uses pseudo-pruning: locally prune for defense while withholding defense-masked weights for future local training instead of deleting them.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]