English

PRIVEE: Privacy-Preserving Vertical Federated Learning Against Feature Inference Attacks

Machine Learning 2025-12-16 v1 Artificial Intelligence

Abstract

Vertical Federated Learning (VFL) enables collaborative model training across organizations that share common user samples but hold disjoint feature spaces. Despite its potential, VFL is susceptible to feature inference attacks, in which adversarial parties exploit shared confidence scores (i.e., prediction probabilities) during inference to reconstruct private input features of other participants. To counter this threat, we propose PRIVEE (PRIvacy-preserving Vertical fEderated lEarning), a novel defense mechanism named after the French word priv\'ee, meaning "private." PRIVEE obfuscates confidence scores while preserving critical properties such as relative ranking and inter-score distances. Rather than exposing raw scores, PRIVEE shares only the transformed representations, mitigating the risk of reconstruction attacks without degrading model prediction accuracy. Extensive experiments show that PRIVEE achieves a threefold improvement in privacy protection compared to state-of-the-art defenses, while preserving full predictive performance against advanced feature inference attacks.

Keywords

Cite

@article{arxiv.2512.12840,
  title  = {PRIVEE: Privacy-Preserving Vertical Federated Learning Against Feature Inference Attacks},
  author = {Sindhuja Madabushi and Ahmad Faraz Khan and Haider Ali and Ananthram Swami and Rui Ning and Hongyi Wu and Jin-Hee Cho},
  journal= {arXiv preprint arXiv:2512.12840},
  year   = {2025}
}

Comments

12 pages, 3 figures

R2 v1 2026-07-01T08:24:17.028Z