Differentially private federated learning for remote sensing with gradient inversion attack mitigation
With the rapid proliferation of remote sensing images in intelligent transportation systems and autonomous driving, the protection of image privacy has become a critical concern. Federated learning (FL) has emerged as a promising paradigm, as it eliminates the need for raw data transmission while reducing communication overhead. Nevertheless, FL remains susceptible to gradient leakage attacks, such as Deep Leakage from Gradients (DLG), which can reconstruct private training data from shared model updates. This work investigates the vulnerability of FL systems to image-level privacy breaches caused by gradient inversion attacks and proposes a defense framework based on differential privacy (DP). In the proposed method, Gaussian noise is injected into client-side model updates after local training, in conjunction with gradient clipping and a uniform noise-scaling mechanism. To evaluate the effectiveness of this approach, extensive experiments are conducted on the EuroSAT, an optical remote sensing image classification task, assessing the trade-off between model performance and privacy protection under varying privacy budgets. Experimental results demonstrate that the proposed DP mechanism substantially reduces the fidelity of reconstructed images, thereby mitigating privacy leakage, while preserving satisfactory classification accuracy. This study provides a systematic analysis of gradient inversion threats in remote-sensing-based FL and introduces a practical defense strategy tailored for security-critical applications.
Paper
Full text
Differentially private federated learning for remote sensing with gradient inversion attack mitigation
OpenAlex · Privacy-Preserving Technologies in Data · 2026
Abstract
With the rapid proliferation of remote sensing images in intelligent transportation systems and autonomous driving, the protection of image privacy has become a critical concern. Federated learning (FL) has emerged as a promising paradigm, as it eliminates the need for raw data transmission while reducing communication overhead. Nevertheless, FL remains susceptible to gradient leakage attacks, such as Deep Leakage from Gradients (DLG), which can reconstruct private training data from shared model updates. This work investigates the vulnerability of FL systems to image-level privacy breaches caused by gradient inversion attacks and proposes a defense framework based on differential privacy (DP). In the proposed method, Gaussian noise is injected into client-side model updates after local training, in conjunction with gradient clipping and a uniform noise-scaling mechanism. To evaluate the effectiveness of this approach, extensive experiments are conducted on the EuroSAT, an optical remote sensing image classification task, assessing the trade-off between model performance and privacy protection under varying privacy budgets. Experimental results demonstrate that the proposed DP mechanism substantially reduces the fidelity of reconstructed images, thereby mitigating privacy leakage, while preserving satisfactory classification accuracy. This study provides a systematic analysis of gradient inversion threats in remote-sensing-based FL and introduces a practical defense strategy tailored for security-critical applications.