Papers
Topics
Authors
Recent
Search
2000 character limit reached

LTP-FLEO: Long-Term Privacy in LEO FL

Updated 9 July 2026
  • LTP-FLEO is an asynchronous federated learning framework designed for LEO satellite networks that secures data privacy over multiple training rounds.
  • It employs privacy-aware satellite partitioning, model age balancing, and fair aggregation to mitigate issues from intermittent visibility and multi-round leakage.
  • Empirical evaluations on datasets like MNIST and EuroSat demonstrate competitive accuracy and enhanced privacy, even in challenging non-IID settings.

LTP-FLEO is an asynchronous federated learning framework for low Earth orbit satellite networks that is designed to preserve long-term privacy across multi-round training rather than only protecting per-round updates. It addresses two limitations of traditional secure aggregation in this setting: the assumption of continuous client availability despite intermittent and irregular satellite visibility, and the neglect of privacy leakage through multiple rounds of plaintext global-model release. Its architecture combines privacy-aware satellite partitioning, model age balancing, and fair global aggregation, with the stated goal of safeguarding both model and data privacy, promoting fairness in line with satellite contributions, accelerating global convergence, and achieving competitive model accuracy (Elmahallawy et al., 19 Aug 2025).

1. Operational setting and the privacy problem it targets

LTP-FLEO is formulated for a satellite network K\mathcal K with KK LEO satellites, grouped into PP orbits, where each satellite kk stores local data

Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.

The global optimization problem is

min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),

with

Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).

The setting is defined by intermittent visibility, asynchronous participation, resource constraints, and a ground-station-centric communication pattern without reliance on inter-satellite links. In standard asynchronous FL, the server broadcasts a global model wt\boldsymbol{w}^t to the currently visible satellites, each visible satellite performs local SGD, encrypts its local model, and participates in secure aggregation. A baseline aggregation rule is

wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,

where K′\mathcal K' is the set of visible satellites in round KK0 (Elmahallawy et al., 19 Aug 2025).

The privacy difficulty arises because secure aggregation protects local models in transit but still releases the global model in plaintext each round. If participation sets vary across rounds and local updates are similar in consecutive rounds, a curious server can approximate an individual client’s update by differencing successive global models. The canonical example is a transition from a round with clients KK1 to a round with KK2, where

KK3

so that KK4. In LEO networks, where participation sets change due to visibility windows, this multi-round leakage channel is structurally amplified (Elmahallawy et al., 19 Aug 2025).

2. Long-term privacy as a formal objective

The central concept of LTP-FLEO is long-term privacy (LTP), defined over the entire training trajectory rather than at a single communication round. Let KK5 denote the plaintext global model at round KK6, and KK7 the local model of client KK8. LTP requires that, for all rounds KK9 and satellites PP0,

PP1

This definition is explicitly stronger than short-term privacy: if LTP holds, then short-term privacy holds automatically, but not conversely (Elmahallawy et al., 19 Aug 2025).

The threat model is honest-but-curious. The ground station and satellites follow the protocol but may attempt to infer local models or underlying data, potentially using multi-round differencing or model inversion. External adversaries are also considered, but the long-term leakage problem is driven primarily by the server’s access to the entire sequence of plaintext global models. LTP-FLEO is therefore designed to ensure that the server can accumulate global models without isolating any individual client’s update over time (Elmahallawy et al., 19 Aug 2025).

3. Protocol design: partitioning, age balancing, and weighted aggregation

The first mechanism is privacy-aware satellite partitioning. Before training, satellite visibility windows are predicted, and satellites are grouped into partitions

PP2

where each partition has cardinality PP3. The parameter PP4 is the LTP level: larger PP5 means that the server only observes sums over larger groups, which strengthens privacy but requires waiting for more satellites to become jointly visible. Partitions are disjoint, and within a partition satellites participate jointly: either all satellites in a partition participate in a round or none do (Elmahallawy et al., 19 Aug 2025).

At round PP6, the framework selects partitions on the basis of overlap in common visibility windows. It defines

PP7

where PP8 is the predicted visibility time of satellite PP9, and then forms a candidate set kk0 consisting of partitions whose common visibility windows overlap with that of kk1. This design ensures that the server only ever obtains sums over fixed partition members, rather than arbitrary and changing subsets of clients (Elmahallawy et al., 19 Aug 2025).

The second mechanism is model age balancing, which mitigates stale-model effects. For a partition kk2, the participation indicator is

kk3

and the participation frequency up to round kk4 is

kk5

Given a tolerance factor kk6, the selected set of partitions is

kk7

If no partition satisfies this condition, the round is skipped. This rule biases participation toward partitions with fresher models while preserving the partition-based privacy structure (Elmahallawy et al., 19 Aug 2025).

The third mechanism is fair global aggregation. For each selected partition kk8, with data size kk9, define

Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.0

Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.1

The aggregation rule becomes

Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.2

The server therefore sees only partition sums Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.3, weighted by data size and participation frequency, rather than individual client models (Elmahallawy et al., 19 Aug 2025).

4. Privacy guarantee, fairness criterion, and convergence analysis

The privacy argument follows directly from the partitioned aggregation structure. Because partitions are disjoint and participation is enforced jointly within each partition, any local model Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.4 always appears only through a partition sum

Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.5

Across rounds, the server may observe different sets of participating partitions, but it never observes partial sums over subsets of a partition. The stated theorem is that, given satellite network Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.6 and partition size Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.7, LTP-FLEO ensures LTP with guarantee level Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.8, while minimizing fairness gap Dk={(xk,j,yk,j)}j=1∣Dk∣.\mathcal{D}_k = \{(x_{k,j}, y_{k,j})\}_{j=1}^{|\mathcal{D}_k|}.9 for a given min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),0 (Elmahallawy et al., 19 Aug 2025).

Fairness is quantified by

min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),1

In the worst-case regime min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),2, all partitions can be selected, and the weighting rule min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),3 is used to drive min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),4 asymptotically while preserving the privacy structure (Elmahallawy et al., 19 Aug 2025).

Convergence is analyzed under standard assumptions: min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),5-smoothness, min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),6-strong convexity, bounded variance of stochastic gradients, and bounded gradient norms. The theorem gives

min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),7

with

min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),8

min⁡w∈RdF(w),F(w)≜1∣D∣∑k∈K∣Dk∣Fk(w),\min_{\boldsymbol{w} \in \mathbb{R}^d} F(\boldsymbol{w}), \quad F(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}|}\sum_{k \in \mathcal{K}} |\mathcal{D}_k| F_k(\boldsymbol{w}),9

The number of rounds needed to reach target accuracy Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).0 is

Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).1

This analysis formalizes the trade-off already implicit in the protocol: larger Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).2 strengthens privacy but can increase waiting time and slow convergence, while age balancing and fairness weighting are intended to reduce the adverse effects of staleness (Elmahallawy et al., 19 Aug 2025).

5. Empirical validation

The reported experimental platform is a Walker-Delta constellation with inclination Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).3, altitude Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).4 km, Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).5 orbits, and Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).6 satellites per orbit, for a total of Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).7 satellites. The ground station is located in the USA with minimum elevation angle Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).8, and visibility is simulated using Ansys STK. The evaluation uses MNIST, CIFAR-10, and EuroSat, with CNNs for MNIST and CIFAR-10 and VGG-16 for EuroSat. Each communication-and-aggregation round takes about Fk(w)≜1∣Dk∣∑(xk,j,yk,j)∈Dkfk(w;xk,j,yk,j).F_k(\boldsymbol{w}) \triangleq \frac{1}{|\mathcal{D}_k|} \sum_{(x_{k,j},y_{k,j})\in \mathcal{D}_k} f_k(\boldsymbol{w}; x_{k,j}, y_{k,j}).9–wt\boldsymbol{w}^t0 minutes, and for different LTP levels wt\boldsymbol{w}^t1, convergence times range from wt\boldsymbol{w}^t2 to wt\boldsymbol{w}^t3 hours on EuroSat (Elmahallawy et al., 19 Aug 2025).

The privacy experiments compare LTP-FLEO with FedSecure under model inversion on EuroSat. FedSecure permits recognizable reconstruction of high-resolution satellite images, whereas LTP-FLEO yields increasingly blurred and unidentifiable reconstructions as wt\boldsymbol{w}^t4 increases. The reported metrics are as follows:

Metric FedSecure LTP-FLEO wt\boldsymbol{w}^t5 LTP-FLEO wt\boldsymbol{w}^t6 LTP-FLEO wt\boldsymbol{w}^t7
PSNR wt\boldsymbol{w}^t8 10.68 5.28 3.03 -1.98
MSE wt\boldsymbol{w}^t9 0.1076 0.528 0.898 1.577
FMSE wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,0 0.1558 1.063 1.926 3.308

These numbers quantify the intended privacy effect: lower PSNR and higher MSE/FMSE indicate stronger obfuscation of client-specific information under multi-round inference attacks (Elmahallawy et al., 19 Aug 2025).

Utility results show that LTP-FLEO remains competitive with AsyncFLEO and outperforms FedAsync in the reported LEO setting. Under IID and non-IID distributions, LTP-FLEO with wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,1 achieves approximately wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,2–wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,3 accuracy on MNIST within wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,4–wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,5 hours, and approximately wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,6–wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,7 on CIFAR-10 in about wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,8 hours. On EuroSat, LTP-FLEO reaches approximately wt+1=∑k∈K′∣Dk∣∣DK′∣wkt,\boldsymbol{w}^{t+1} = \sum_{k\in \mathcal K'} \frac{|\mathcal{D}_k|}{|\mathcal{D}_{\mathcal K'}|} \boldsymbol{w}_k^t,9 accuracy after only K′\mathcal K'0 hours. In the non-IID EuroSat setting, with satellites in different orbits each owning data from only K′\mathcal K'1 classes, the confusion matrix is reported as balanced across all K′\mathcal K'2 classes, which the authors attribute to the fair aggregation weights K′\mathcal K'3 (Elmahallawy et al., 19 Aug 2025).

6. Scope, assumptions, and terminological boundaries

LTP-FLEO assumes predictable satellite visibility, an honest-but-curious threat model, and a ground-station-centric architecture without inter-satellite links. It does not target fully malicious behavior such as model poisoning, and it inherits an explicit design trade-off in partition size K′\mathcal K'4: larger K′\mathcal K'5 provides stronger long-term privacy, but increases the time required for full partitions to become jointly visible and can slow convergence. The framework is positioned as a practical alternative to fully encrypted FL over all rounds, which is described as computationally infeasible in resource-constrained satellite settings (Elmahallawy et al., 19 Aug 2025).

A common misconception is to conflate this term with other unrelated acronym families. In the arXiv literature, “Learned Token Pruning” is a transformer inference method abbreviated LTP (Kim et al., 2021), “FLoE” denotes a Fisher-based PEFT method for sparse adaptation of low-rank experts (Wang et al., 31 May 2025), and “Floe” denotes a hybrid federated edge–cloud framework for real-time LLM–SLM inference (Tian et al., 15 Feb 2026). None of these works defines LTP-FLEO as used here. In its explicit and paper-defined sense, LTP-FLEO refers to long-term privacy for asynchronous federated learning in LEO satellite networks (Elmahallawy et al., 19 Aug 2025).

Topic to Video (Beta)

No one has generated a video about this topic yet.

Whiteboard

No one has generated a whiteboard explanation for this topic yet.

Follow Topic

Get notified by email when new papers are published related to LTP-FLEO.