{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,19]],"date-time":"2026-06-19T16:29:05Z","timestamp":1781886545770,"version":"3.54.5"},"reference-count":45,"publisher":"MDPI AG","issue":"24","license":[{"start":{"date-parts":[[2020,12,15]],"date-time":"2020-12-15T00:00:00Z","timestamp":1607990400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"KAKENHI Young Researcher","award":["20K19931"],"award-info":[{"award-number":["20K19931"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>With the advent of smart devices, smartphones, and smart everything, the Internet of Things (IoT) has emerged with an incredible impact on the industries and human life. The IoT consists of millions of clients that exchange massive amounts of critical data, which results in high privacy risks when processed by a centralized cloud server. Motivated by this privacy concern, a new machine learning paradigm has emerged, namely Federated Learning (FL). Specifically, FL allows for each client to train a learning model locally and performs global model aggregation at the centralized cloud server in order to avoid the direct data leakage from clients. However, despite this efficient distributed training technique, an individual\u2019s private information can still be compromised. To this end, in this paper, we investigate the privacy and security threats that can harm the whole execution process of FL. Additionally, we provide practical solutions to overcome those attacks and protect the individual\u2019s privacy. We also present experimental results in order to highlight the discussed issues and possible solutions. We expect that this work will open exciting perspectives for future research in FL.<\/jats:p>","DOI":"10.3390\/s20247182","type":"journal-article","created":{"date-parts":[[2020,12,15]],"date-time":"2020-12-15T09:12:57Z","timestamp":1608023577000},"page":"7182","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":48,"title":["A Critical Evaluation of Privacy and Security Threats in Federated Learning"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0036-1714","authenticated-orcid":false,"given":"Muhammad","family":"Asad","sequence":"first","affiliation":[{"name":"Department of Computer Science, Nagoya Institute of Technology, Nagoya 466-8555, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ahmed","family":"Moustafa","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Nagoya Institute of Technology, Nagoya 466-8555, Japan"},{"name":"Faculty of Informatics, Zagazig University, Zagazig 44519, Egypt"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chao","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Data and Computer Science, Sun Yat-Sen University, Guangzhou 510275, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,12,15]]},"reference":[{"key":"ref_1","first-page":"1","article-title":"Internet of Things (IoT) and new computing paradigms","volume":"6","author":"Chang","year":"2019","journal-title":"Fog Edge Comput. Princ. Paradig."},{"key":"ref_2","unstructured":"Kone\u010dn\u00fd, J., McMahan, H.B., Ramage, D., and Richt\u00e1rik, P. (2016). Federated optimization: Distributed machine learning for on-device intelligence. arXiv."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1002\/hbe2.117","article-title":"Human-centered artificial intelligence and machine learning","volume":"1","author":"Riedl","year":"2019","journal-title":"Hum. Behav. Emerg. Technol."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1353\/jod.2019.0003","article-title":"The road to digital unfreedom: How artificial intelligence is reshaping repression","volume":"30","author":"Feldstein","year":"2019","journal-title":"J. Democr."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Cui, H., Radosavljevic, V., Chou, F.C., Lin, T.H., Nguyen, T., Huang, T.K., Schneider, J., and Djuric, N. (2019, January 20\u201324). Multimodal trajectory predictions for autonomous driving using deep convolutional networks. Proceedings of the 2019 International Conference on Robotics and Automation (ICRA), Montreal, QC, Canada.","DOI":"10.1109\/ICRA.2019.8793868"},{"key":"ref_6","first-page":"651","article-title":"Arabic Voice Recognition Using Fuzzy Logic and Neural Network","volume":"14","author":"Eljawad","year":"2019","journal-title":"Int. J. Appl. Eng. Res."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"362","DOI":"10.1080\/02684527.2019.1553701","article-title":"Is social media intelligence private? Privacy in public and the nature of social media intelligence","volume":"34","year":"2019","journal-title":"Intell. Natl. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Nayak, S.K., and Ojha, A.C. (2020). Data Leakage Detection and Prevention: Review and Research Directions. Machine Learning and Information Processing, Springer.","DOI":"10.1007\/978-981-15-1884-3_19"},{"key":"ref_9","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., and y Arcas, B.A. (2017, January 20\u201322). Communication-efficient learning of deep networks from decentralized data. Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS), Fort Lauderdale, FL, USA."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Asad, M., Moustafa, A., Ito, T., and Aslam, M. (2020). Evaluating the Communication Efficiency in Federated Learning Algorithms. arXiv.","DOI":"10.1109\/CSCWD49262.2021.9437738"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"4177","DOI":"10.1109\/TII.2019.2942190","article-title":"Blockchain and federated learning for privacy-preserved data sharing in industrial IoT","volume":"16","author":"Lu","year":"2019","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Dwork, C., McSherry, F., Nissim, K., and Smith, A. (2006). Calibrating noise to sensitivity in private data analysis. Theory of Cryptography Conference, Springer.","DOI":"10.1007\/11681878_14"},{"key":"ref_13","unstructured":"Papernot, N., Abadi, M., Erlingsson, U., Goodfellow, I., and Talwar, K. (2016). Semi-supervised knowledge transfer for deep learning from private training data. arXiv."},{"key":"ref_14","first-page":"1333","article-title":"Privacy-preserving deep learning via additively homomorphic encryption","volume":"13","author":"Aono","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3339474","article-title":"Federated machine learning: Concept and applications","volume":"10","author":"Yang","year":"2019","journal-title":"ACM Trans. Intell. Syst. Technol. (TIST)"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Wang, Z., Song, M., Zhang, Z., Song, Y., Wang, Q., and Qi, H. (May, January 29). Beyond inferring class representatives: User-level privacy leakage from federated learning. Proceedings of the IEEE INFOCOM 2019\u2014IEEE Conference on Computer Communications, Paris, France.","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref_17","unstructured":"Li, Q., Wen, Z., and He, B. (2019). Federated learning systems: Vision, hype and reality for data privacy and protection. arXiv."},{"key":"ref_18","unstructured":"Bae, H., Jang, J., Jung, D., Jang, H., Ha, H., and Yoon, S. (2018). Security and privacy issues in deep learning. arXiv."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Nishio, T., and Yonetani, R. (2019, January 21\u201323). Client selection for federated learning with heterogeneous resources in mobile edge. Proceedings of the ICC 2019\u20142019 IEEE International Conference on Communications (ICC), Shanghai, China.","DOI":"10.1109\/ICC.2019.8761315"},{"key":"ref_20","unstructured":"Kim, H., Park, J., Bennis, M., and Kim, S.L. (2018). On-device federated learning via blockchain and its latency analysis. arXiv."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Zhao, L., Ni, L., Hu, S., Chen, Y., Zhou, P., Xiao, F., and Wu, L. (2018, January 15\u201319). Inprivate digging: Enabling tree-based distributed data mining with differential privacy. Proceedings of the IEEE INFOCOM 2018\u2014IEEE Conference on Computer Communications, Honolulu, HI, USA.","DOI":"10.1109\/INFOCOM.2018.8486352"},{"key":"ref_22","unstructured":"Bhagoji, A.N., Chakraborty, S., Mittal, P., and Calo, S. (2019, January 10\u201315). Analyzing federated learning through an adversarial lens. Proceedings of the International Conference on Machine Learning, Long Beach, CA, USA."},{"key":"ref_23","unstructured":"Segal, A., Marcedone, A., Kreuter, B., Ramage, D., McMahan, H.B., Seth, K., Patel, S., Bonawitz, K., and Ivanov, V. (November, January 30). Practical secure aggregation for privacy-preserving machine learning. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Liu, Y., Ma, Z., Liu, X., Ma, S., Nepal, S., and Deng, R. (2019). Boosting privately: Privacy-preserving federated extreme boosting for mobile crowdsensing. arXiv.","DOI":"10.1109\/ICDCS47774.2020.00017"},{"key":"ref_25","unstructured":"Cheng, K., Fan, T., Jin, Y., Liu, Y., Chen, T., and Yang, Q. (2019). Secureboost: A lossless federated learning framework. arXiv."},{"key":"ref_26","unstructured":"Li, T., Sanjabi, M., Beirami, A., and Smith, V. (2019). Fair resource allocation in federated learning. arXiv."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Asad, M., Moustafa, A., and Ito, T. (2020). FedOpt: Towards Communication Efficiency and Privacy Preservation in Federated Learning. Appl. Sci., 10.","DOI":"10.3390\/app10082864"},{"key":"ref_28","unstructured":"Fang, M., Cao, X., Jia, J., and Gong, N. (2020, January 12\u201314). Local model poisoning attacks to Byzantine-robust federated learning. Proceedings of the 29th USENIX Security Symposium (USENIX Security 20), Boston, MA, USA."},{"key":"ref_29","unstructured":"Bhowmick, A., Duchi, J., Freudiger, J., Kapoor, G., and Rogers, R. (2018). Protection against reconstruction and its applications in private federated learning. arXiv."},{"key":"ref_30","unstructured":"Xie, C., Huang, K., Chen, P.Y., and Li, B. (2019, January 6\u20139). DBA: Distributed Backdoor Attacks against Federated Learning. Proceedings of the International Conference on Learning Representations, New Orleans, LA, USA."},{"key":"ref_31","unstructured":"Li, Q., Wen, Z., and He, B. (2020, January 7\u201312). Practical Federated Gradient Boosting Decision Trees. Proceedings of the AAAI, New York, NY, USA."},{"key":"ref_32","unstructured":"Sahu, A.K., Li, T., Sanjabi, M., Zaheer, M., Talwalkar, A., and Smith, V. (2018). On the convergence of federated optimization in heterogeneous networks. arXiv."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"10700","DOI":"10.1109\/JIOT.2019.2940820","article-title":"Incentive mechanism for reliable federated learning: A joint optimization approach to combining reputation and contract theory","volume":"6","author":"Kang","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Truex, S., Baracaldo, N., Anwar, A., Steinke, T., Ludwig, H., Zhang, R., and Zhou, Y. (2019, January 11\u201315). A hybrid approach to privacy-preserving federated learning. Proceedings of the 12th ACM Workshop on Artificial Intelligence and Security, London, UK.","DOI":"10.1145\/3338501.3357370"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"So, J., Guler, B., and Avestimehr, A.S. (2020). Byzantine-resilient secure federated learning. arXiv.","DOI":"10.1109\/JSAC.2020.3041404"},{"key":"ref_36","unstructured":"Liu, Y., Kang, Y., Zhang, X., Li, L., Cheng, Y., Chen, T., Hong, M., and Yang, Q. (2019). A communication efficient vertical federated learning framework. arXiv."},{"key":"ref_37","unstructured":"McMahan, H.B., Ramage, D., Talwar, K., and Zhang, L. (2017). Learning differentially private recurrent language models. arXiv."},{"key":"ref_38","unstructured":"Liu, Y., Liu, Y., Liu, Z., Liang, Y., Meng, C., Zhang, J., and Zheng, Y. (2020). Federated forest. IEEE Trans. Big Data."},{"key":"ref_39","unstructured":"Hardy, S., Henecka, W., Ivey-Law, H., Nock, R., Patrini, G., Smith, G., and Thorne, B. (2017). Private federated learning on vertically partitioned data via entity resolution and additively homomorphic encryption. arXiv."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Sanil, A.P., Karr, A.F., Lin, X., and Reiter, J.P. (2004, January 22\u201325). Privacy preserving regression modelling via distributed computation. Proceedings of the Tenth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Seattle, WA, USA.","DOI":"10.1145\/1014052.1014139"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"34","DOI":"10.1016\/j.ins.2018.03.061","article-title":"Privacy-preserving ridge regression on distributed data","volume":"451","author":"Chen","year":"2018","journal-title":"Inf. Sci."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Nikolaenko, V., Weinsberg, U., Ioannidis, S., Joye, M., Boneh, D., and Taft, N. (2013, January 19\u201322). Privacy-preserving ridge regression on hundreds of millions of records. Proceedings of the 2013 IEEE Symposium on Security and Privacy, Berkeley, CA, USA.","DOI":"10.1109\/SP.2013.30"},{"key":"ref_43","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., and Shmatikov, V. (2020, January 3\u20135). How to backdoor federated learning. Proceedings of the International Conference on Artificial Intelligence and Statistics, Palermo, Italy."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"242","DOI":"10.1109\/MNET.001.1900506","article-title":"On Safeguarding Privacy and Security in the Framework of Federated Learning","volume":"34","author":"Ma","year":"2020","journal-title":"IEEE Netw."},{"key":"ref_45","unstructured":"Kairouz, P., McMahan, H.B., Avent, B., Bellet, A., Bennis, M., Bhagoji, A.N., Bonawitz, K., Charles, Z., Cormode, G., and d\u2019Oliveira, R.G. (2019). Advances and open problems in federated learning. arXiv."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/24\/7182\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T10:45:15Z","timestamp":1760179515000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/24\/7182"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,12,15]]},"references-count":45,"journal-issue":{"issue":"24","published-online":{"date-parts":[[2020,12]]}},"alternative-id":["s20247182"],"URL":"https:\/\/doi.org\/10.3390\/s20247182","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,12,15]]}}}