Skip to main navigation Skip to search Skip to main content

FedLeaks: Creating Timing Channel Leaks in Federated Learning of Adaptive Neural Networks

  • Stevens Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Previous work [6, 28, 38] has demonstrated the vulnerability of adaptive neural networks (AdNNs) to privacy attacks via timing channels. While these privacy attacks may leak sensitive information about user-provided input, not all AdNNs are vulnerable, and an attacker's success is directly related to degree of vulnerability in the target AdNN. Previous work has assumed an adversary entirely removed from the AdNN's training process; however, in many real-world settings, an adversary may possess both the capability and incentive to influence the AdNN training in order to deliberately create privacy-compromising timing channels within it.In this work, we investigate scenarios where an adversary can intentionally craft timing channels in AdNNs in order to later launch privacy attacks. Our study focuses on the federated learning of AdNNs, where multiple parties collaboratively train a shared model without directly exchanging their private datasets. We propose FedLeaks, a method for crafting timing channels in AdNNs, and evaluate FedLeaks on three datasets and three AdNN architectures. Our experiments show that FedLeaks can effectively introduce strong timing channels in AdNNs compared to benign training strategies without any adversarial influence.We further demonstrate that existing mitigation strategies, while effective against the benignly-introduced timing channels previously studied, fail to adequately defend against timing channels crafted using FedLeaks. In these cases, mitigation leads to significant accuracy and/or efficiency degradation, making the model impractical without extensive retraining or redevelopment. Overall, Our findings demonstrate that an informed adversary can maliciously introduce exploitable timing channels into AdNNs, undermining model trustworthiness and exposing users to privacy risks.

Original languageEnglish
Title of host publicationASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
Pages1125-1138
Number of pages14
ISBN (Electronic)9798400723568
DOIs
StatePublished - 4 Jun 2026
Event21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026 - Bangalore, India
Duration: 1 Jun 20265 Jun 2026

Publication series

NameASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security

Conference

Conference21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026
Country/TerritoryIndia
CityBangalore
Period1/06/265/06/26

Keywords

  • Adaptive neural networks
  • Federated learning
  • Timing channels

Fingerprint

Dive into the research topics of 'FedLeaks: Creating Timing Channel Leaks in Federated Learning of Adaptive Neural Networks'. Together they form a unique fingerprint.

Cite this