LTP-FLEO: Long-Term Privacy in LEO FL
- LTP-FLEO is an asynchronous federated learning framework designed for LEO satellite networks that secures data privacy over multiple training rounds.
- It employs privacy-aware satellite partitioning, model age balancing, and fair aggregation to mitigate issues from intermittent visibility and multi-round leakage.
- Empirical evaluations on datasets like MNIST and EuroSat demonstrate competitive accuracy and enhanced privacy, even in challenging non-IID settings.
LTP-FLEO is an asynchronous federated learning framework for low Earth orbit satellite networks that is designed to preserve long-term privacy across multi-round training rather than only protecting per-round updates. It addresses two limitations of traditional secure aggregation in this setting: the assumption of continuous client availability despite intermittent and irregular satellite visibility, and the neglect of privacy leakage through multiple rounds of plaintext global-model release. Its architecture combines privacy-aware satellite partitioning, model age balancing, and fair global aggregation, with the stated goal of safeguarding both model and data privacy, promoting fairness in line with satellite contributions, accelerating global convergence, and achieving competitive model accuracy (Elmahallawy et al., 19 Aug 2025).
1. Operational setting and the privacy problem it targets
LTP-FLEO is formulated for a satellite network with LEO satellites, grouped into orbits, where each satellite stores local data
The global optimization problem is
with
The setting is defined by intermittent visibility, asynchronous participation, resource constraints, and a ground-station-centric communication pattern without reliance on inter-satellite links. In standard asynchronous FL, the server broadcasts a global model to the currently visible satellites, each visible satellite performs local SGD, encrypts its local model, and participates in secure aggregation. A baseline aggregation rule is
where is the set of visible satellites in round 0 (Elmahallawy et al., 19 Aug 2025).
The privacy difficulty arises because secure aggregation protects local models in transit but still releases the global model in plaintext each round. If participation sets vary across rounds and local updates are similar in consecutive rounds, a curious server can approximate an individual client’s update by differencing successive global models. The canonical example is a transition from a round with clients 1 to a round with 2, where
3
so that 4. In LEO networks, where participation sets change due to visibility windows, this multi-round leakage channel is structurally amplified (Elmahallawy et al., 19 Aug 2025).
2. Long-term privacy as a formal objective
The central concept of LTP-FLEO is long-term privacy (LTP), defined over the entire training trajectory rather than at a single communication round. Let 5 denote the plaintext global model at round 6, and 7 the local model of client 8. LTP requires that, for all rounds 9 and satellites 0,
1
This definition is explicitly stronger than short-term privacy: if LTP holds, then short-term privacy holds automatically, but not conversely (Elmahallawy et al., 19 Aug 2025).
The threat model is honest-but-curious. The ground station and satellites follow the protocol but may attempt to infer local models or underlying data, potentially using multi-round differencing or model inversion. External adversaries are also considered, but the long-term leakage problem is driven primarily by the server’s access to the entire sequence of plaintext global models. LTP-FLEO is therefore designed to ensure that the server can accumulate global models without isolating any individual client’s update over time (Elmahallawy et al., 19 Aug 2025).
3. Protocol design: partitioning, age balancing, and weighted aggregation
The first mechanism is privacy-aware satellite partitioning. Before training, satellite visibility windows are predicted, and satellites are grouped into partitions
2
where each partition has cardinality 3. The parameter 4 is the LTP level: larger 5 means that the server only observes sums over larger groups, which strengthens privacy but requires waiting for more satellites to become jointly visible. Partitions are disjoint, and within a partition satellites participate jointly: either all satellites in a partition participate in a round or none do (Elmahallawy et al., 19 Aug 2025).
At round 6, the framework selects partitions on the basis of overlap in common visibility windows. It defines
7
where 8 is the predicted visibility time of satellite 9, and then forms a candidate set 0 consisting of partitions whose common visibility windows overlap with that of 1. This design ensures that the server only ever obtains sums over fixed partition members, rather than arbitrary and changing subsets of clients (Elmahallawy et al., 19 Aug 2025).
The second mechanism is model age balancing, which mitigates stale-model effects. For a partition 2, the participation indicator is
3
and the participation frequency up to round 4 is
5
Given a tolerance factor 6, the selected set of partitions is
7
If no partition satisfies this condition, the round is skipped. This rule biases participation toward partitions with fresher models while preserving the partition-based privacy structure (Elmahallawy et al., 19 Aug 2025).
The third mechanism is fair global aggregation. For each selected partition 8, with data size 9, define
0
1
The aggregation rule becomes
2
The server therefore sees only partition sums 3, weighted by data size and participation frequency, rather than individual client models (Elmahallawy et al., 19 Aug 2025).
4. Privacy guarantee, fairness criterion, and convergence analysis
The privacy argument follows directly from the partitioned aggregation structure. Because partitions are disjoint and participation is enforced jointly within each partition, any local model 4 always appears only through a partition sum
5
Across rounds, the server may observe different sets of participating partitions, but it never observes partial sums over subsets of a partition. The stated theorem is that, given satellite network 6 and partition size 7, LTP-FLEO ensures LTP with guarantee level 8, while minimizing fairness gap 9 for a given 0 (Elmahallawy et al., 19 Aug 2025).
Fairness is quantified by
1
In the worst-case regime 2, all partitions can be selected, and the weighting rule 3 is used to drive 4 asymptotically while preserving the privacy structure (Elmahallawy et al., 19 Aug 2025).
Convergence is analyzed under standard assumptions: 5-smoothness, 6-strong convexity, bounded variance of stochastic gradients, and bounded gradient norms. The theorem gives
7
with
8
9
The number of rounds needed to reach target accuracy 0 is
1
This analysis formalizes the trade-off already implicit in the protocol: larger 2 strengthens privacy but can increase waiting time and slow convergence, while age balancing and fairness weighting are intended to reduce the adverse effects of staleness (Elmahallawy et al., 19 Aug 2025).
5. Empirical validation
The reported experimental platform is a Walker-Delta constellation with inclination 3, altitude 4 km, 5 orbits, and 6 satellites per orbit, for a total of 7 satellites. The ground station is located in the USA with minimum elevation angle 8, and visibility is simulated using Ansys STK. The evaluation uses MNIST, CIFAR-10, and EuroSat, with CNNs for MNIST and CIFAR-10 and VGG-16 for EuroSat. Each communication-and-aggregation round takes about 9–0 minutes, and for different LTP levels 1, convergence times range from 2 to 3 hours on EuroSat (Elmahallawy et al., 19 Aug 2025).
The privacy experiments compare LTP-FLEO with FedSecure under model inversion on EuroSat. FedSecure permits recognizable reconstruction of high-resolution satellite images, whereas LTP-FLEO yields increasingly blurred and unidentifiable reconstructions as 4 increases. The reported metrics are as follows:
| Metric | FedSecure | LTP-FLEO 5 | LTP-FLEO 6 | LTP-FLEO 7 |
|---|---|---|---|---|
| PSNR 8 | 10.68 | 5.28 | 3.03 | -1.98 |
| MSE 9 | 0.1076 | 0.528 | 0.898 | 1.577 |
| FMSE 0 | 0.1558 | 1.063 | 1.926 | 3.308 |
These numbers quantify the intended privacy effect: lower PSNR and higher MSE/FMSE indicate stronger obfuscation of client-specific information under multi-round inference attacks (Elmahallawy et al., 19 Aug 2025).
Utility results show that LTP-FLEO remains competitive with AsyncFLEO and outperforms FedAsync in the reported LEO setting. Under IID and non-IID distributions, LTP-FLEO with 1 achieves approximately 2–3 accuracy on MNIST within 4–5 hours, and approximately 6–7 on CIFAR-10 in about 8 hours. On EuroSat, LTP-FLEO reaches approximately 9 accuracy after only 0 hours. In the non-IID EuroSat setting, with satellites in different orbits each owning data from only 1 classes, the confusion matrix is reported as balanced across all 2 classes, which the authors attribute to the fair aggregation weights 3 (Elmahallawy et al., 19 Aug 2025).
6. Scope, assumptions, and terminological boundaries
LTP-FLEO assumes predictable satellite visibility, an honest-but-curious threat model, and a ground-station-centric architecture without inter-satellite links. It does not target fully malicious behavior such as model poisoning, and it inherits an explicit design trade-off in partition size 4: larger 5 provides stronger long-term privacy, but increases the time required for full partitions to become jointly visible and can slow convergence. The framework is positioned as a practical alternative to fully encrypted FL over all rounds, which is described as computationally infeasible in resource-constrained satellite settings (Elmahallawy et al., 19 Aug 2025).
A common misconception is to conflate this term with other unrelated acronym families. In the arXiv literature, “Learned Token Pruning” is a transformer inference method abbreviated LTP (Kim et al., 2021), “FLoE” denotes a Fisher-based PEFT method for sparse adaptation of low-rank experts (Wang et al., 31 May 2025), and “Floe” denotes a hybrid federated edge–cloud framework for real-time LLM–SLM inference (Tian et al., 15 Feb 2026). None of these works defines LTP-FLEO as used here. In its explicit and paper-defined sense, LTP-FLEO refers to long-term privacy for asynchronous federated learning in LEO satellite networks (Elmahallawy et al., 19 Aug 2025).