TY - GEN
T1 - FedLeaks
T2 - 21st ACM Asia Conference on Computer and Communications Security, AsiaCCS 2026
AU - Akinsanya, Ayomide
AU - Brennan, Tegan
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s).
PY - 2026/6/4
Y1 - 2026/6/4
N2 - Previous work [6, 28, 38] has demonstrated the vulnerability of adaptive neural networks (AdNNs) to privacy attacks via timing channels. While these privacy attacks may leak sensitive information about user-provided input, not all AdNNs are vulnerable, and an attacker's success is directly related to degree of vulnerability in the target AdNN. Previous work has assumed an adversary entirely removed from the AdNN's training process; however, in many real-world settings, an adversary may possess both the capability and incentive to influence the AdNN training in order to deliberately create privacy-compromising timing channels within it.In this work, we investigate scenarios where an adversary can intentionally craft timing channels in AdNNs in order to later launch privacy attacks. Our study focuses on the federated learning of AdNNs, where multiple parties collaboratively train a shared model without directly exchanging their private datasets. We propose FedLeaks, a method for crafting timing channels in AdNNs, and evaluate FedLeaks on three datasets and three AdNN architectures. Our experiments show that FedLeaks can effectively introduce strong timing channels in AdNNs compared to benign training strategies without any adversarial influence.We further demonstrate that existing mitigation strategies, while effective against the benignly-introduced timing channels previously studied, fail to adequately defend against timing channels crafted using FedLeaks. In these cases, mitigation leads to significant accuracy and/or efficiency degradation, making the model impractical without extensive retraining or redevelopment. Overall, Our findings demonstrate that an informed adversary can maliciously introduce exploitable timing channels into AdNNs, undermining model trustworthiness and exposing users to privacy risks.
AB - Previous work [6, 28, 38] has demonstrated the vulnerability of adaptive neural networks (AdNNs) to privacy attacks via timing channels. While these privacy attacks may leak sensitive information about user-provided input, not all AdNNs are vulnerable, and an attacker's success is directly related to degree of vulnerability in the target AdNN. Previous work has assumed an adversary entirely removed from the AdNN's training process; however, in many real-world settings, an adversary may possess both the capability and incentive to influence the AdNN training in order to deliberately create privacy-compromising timing channels within it.In this work, we investigate scenarios where an adversary can intentionally craft timing channels in AdNNs in order to later launch privacy attacks. Our study focuses on the federated learning of AdNNs, where multiple parties collaboratively train a shared model without directly exchanging their private datasets. We propose FedLeaks, a method for crafting timing channels in AdNNs, and evaluate FedLeaks on three datasets and three AdNN architectures. Our experiments show that FedLeaks can effectively introduce strong timing channels in AdNNs compared to benign training strategies without any adversarial influence.We further demonstrate that existing mitigation strategies, while effective against the benignly-introduced timing channels previously studied, fail to adequately defend against timing channels crafted using FedLeaks. In these cases, mitigation leads to significant accuracy and/or efficiency degradation, making the model impractical without extensive retraining or redevelopment. Overall, Our findings demonstrate that an informed adversary can maliciously introduce exploitable timing channels into AdNNs, undermining model trustworthiness and exposing users to privacy risks.
KW - Adaptive neural networks
KW - Federated learning
KW - Timing channels
UR - https://www.scopus.com/pages/publications/105042451391
UR - https://www.scopus.com/pages/publications/105042451391#tab=citedBy
U2 - 10.1145/3779208.3785394
DO - 10.1145/3779208.3785394
M3 - Conference contribution
AN - SCOPUS:105042451391
T3 - ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
SP - 1125
EP - 1138
BT - ASIA CCS 2026 - Proceedings of the 21st ACM ASIA Conference on Computer and Communications Security
Y2 - 1 June 2026 through 5 June 2026
ER -