Leakage auditing at frontier scale

Establish methods for quantifying residual leakage from shared federated-learning weights under realistic multi-site conditions and for tracing that leakage to a responsible participant.

Background

Federated learning keeps raw data at participating institutions, but model weights, gradients, metrics, and outputs may still reveal sensitive information. The paper notes that production privacy practices generally begin with a threat model, yet the residual leakage associated with shared model updates has not been adequately assessed in realistic, frontier-scale deployments.

The paper also highlights attribution as a separate unresolved requirement: when leakage occurs, operators need to determine which participant was responsible. Such auditing and attribution are important for accountability in cross-institutional federations.

References

Best practices presume a threat model, but quantifying residual leakage from shared weights under realistic multi-site conditions is unvalidated at frontier scale, as is tracing leakage to a responsible participant.

— From Pilots to Production: Lessons in Cross-Institutional Federated Training and Artificial Intelligence for Science  (2609.39803 - Kotevska et al., 30 Sep 2026) in Section 4, “What Remains Unsolved, and a Shared Agenda”