AI Security

Federated Learning Privacy Checker

Audit a federated learning deployment across secure aggregation, differential privacy composition, poisoning resistance and gradient inversion risk, and see which privacy claims the design actually supports.

Last reviewed by the Radiatus Cloud team

Results appear here.

Securing AI in production?

We build guardrails, governance & compliance for AI systems.

Talk to an AI advisor

Not moving the data is not the same as not exposing it

Federated learning is frequently presented as privacy-preserving because raw data never leaves the device. What leaves the device is a model update computed from that data, and an individual update carries a great deal of information about the examples that produced it. Published gradient inversion work reconstructs recognisable training inputs from updates alone, and the attack is most effective at exactly the small batch sizes on-device training tends to use. Without secure aggregation and a noise mechanism, federated learning changes what is transmitted rather than how much is revealed.

Secure aggregation and differential privacy solve different problems

Secure aggregation stops the server seeing who contributed what; it says nothing about what the aggregate itself reveals. Differential privacy bounds what the released model reveals about any individual, but does not prevent the server inspecting individual updates on the way. They are complementary, and a deployment with one is commonly described as though it had both. The distinction matters because the attacks they stop are different attacks.

The budget composes across rounds, and training has many rounds

Each training round releases information, so the privacy budget accumulates over every round the model trains for. A per-round epsilon chosen because it looked reasonable in isolation composes across hundreds of rounds into a total that bounds nothing. This is the most common error in federated deployments and the easiest to check: ask what the total epsilon is across the whole training run, and whether anyone computed it before training rather than after.

Related tools

Frequently Asked Questions

Does federated learning remove privacy risk?

No. It changes what is transmitted. Model updates carry substantial information about the data that produced them, and gradient inversion recovers recognisable inputs, particularly at the small batch sizes on-device training uses.

What does secure aggregation protect against?

The server seeing individual client updates. It does not bound what the aggregate reveals, which is a different problem that only a noise mechanism addresses.

Why does the round count matter?

Because each round is a release and the privacy budget composes across all of them. A per-round epsilon that looks strong in isolation composes into a total that bounds nothing.

Can one client poison the model?

With simple averaging, yes, and substantially. Robust aggregation such as a trimmed mean or median bounds the influence of outliers, but it assumes a bounded fraction of malicious clients, which depends on identity controls.

Do data protection obligations still apply?

Yes. Processing personal data on the device is still processing, and the people whose data trains the model retain their information rights whether or not the data leaves the device.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Tick the protections in place to score the deployment.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.