TY - JOUR
T1 - Adaptive Differential Privacy Noise Injection for Decentralized Federated Learning of Visual Recognition Tasks
AU - Ouyang, Junyan
AU - Du, Siqi
AU - Han, Rui
AU - Liu, Chi Harold
AU - Zhao, Jianxin
AU - Wu, Xiaoning
AU - Chen, Lydia Y.
N1 - Publisher Copyright:
© The Author(s), under exclusive licence to Springer Science+Business Media, LLC, part of Springer Nature 2026.
PY - 2026/8
Y1 - 2026/8
N2 - With the growing volume of Internet of Things (IoT) data acquired in edge-side visual recognition applications, peer-to-peer decentralized federated learning (DFL) has emerged as an attractive model training paradigm. Unlike centralized FL where a server aggregates per-round client updates, DFL clients directly exchange sparsified model parameters (only a subset is transmitted each round). The exchanged parameters embed accumulated training history rather than independent round updates. This creates a fundamental dilemma for privacy protection with differential privacy (DP): to prevent historical leakage, existing methods are forced to update only the small fraction (e.g., 10%) of parameters currently being exchanged and protected by DP noise, leaving most parameters frozen and severely degrading accuracy. In this paper, we propose DecentDP, an approach that addresses this dilemma to improve model accuracy. The two key modules of DecentDP are: (i) a parameter selector that designates a subset of parameters for local-only updates, allowing them to be updated without DP noise; and (ii) a noise injector that adaptively adds less DP noise to exchangeable parameters that are more sensitive to DP noise. Experiments across five settings show that DecentDP outperforms 11 baselines, achieving an average accuracy improvement of 15.68%, with only 0.70% additional computational overhead and 0.60% additional communication overhead.
AB - With the growing volume of Internet of Things (IoT) data acquired in edge-side visual recognition applications, peer-to-peer decentralized federated learning (DFL) has emerged as an attractive model training paradigm. Unlike centralized FL where a server aggregates per-round client updates, DFL clients directly exchange sparsified model parameters (only a subset is transmitted each round). The exchanged parameters embed accumulated training history rather than independent round updates. This creates a fundamental dilemma for privacy protection with differential privacy (DP): to prevent historical leakage, existing methods are forced to update only the small fraction (e.g., 10%) of parameters currently being exchanged and protected by DP noise, leaving most parameters frozen and severely degrading accuracy. In this paper, we propose DecentDP, an approach that addresses this dilemma to improve model accuracy. The two key modules of DecentDP are: (i) a parameter selector that designates a subset of parameters for local-only updates, allowing them to be updated without DP noise; and (ii) a noise injector that adaptively adds less DP noise to exchangeable parameters that are more sensitive to DP noise. Experiments across five settings show that DecentDP outperforms 11 baselines, achieving an average accuracy improvement of 15.68%, with only 0.70% additional computational overhead and 0.60% additional communication overhead.
KW - Adaptive noise injection
KW - Decentralized federated learning
KW - Differential privacy
KW - Model parameter
UR - https://www.scopus.com/pages/publications/105045348618
U2 - 10.1007/s11263-026-02969-y
DO - 10.1007/s11263-026-02969-y
M3 - Article
AN - SCOPUS:105045348618
SN - 0920-5691
VL - 134
JO - International Journal of Computer Vision
JF - International Journal of Computer Vision
IS - 8
M1 - 358
ER -