IP Library › Granted Patent US 12,634,328
Granted Patent B2
US 12,634,328 · App. 18/639,853 · Granted May 19, 2026

Automating model inversion defense selection for heterogeneous federated learning

Inventors: Pablo Nascimento da Silva (Niterói, BR); Isabella Costa Maia (São Paulo, BR); Iam Palatnik de Sousa (Rio de Janeiro, BR); Eduarda Tatiane Caetano Chagas (Belo Horizonte, BR); Maira Beatriz Hernandez Moran (Rio de Janeiro, BR); Paulo Abelha Ferreira (Rio de Janeiro, BR)
Assignee: Dell Products L.P.
H04L63/1433G06N3/045G06N3/098
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,328
App. No.
18/639,853
Granted
May 19, 2026
Kind
B2
Abstract

One example method includes allocating defense methods to nodes of a federation according to respective resources available at the nodes, testing the nodes by causing the defense methods to be run at the nodes, collecting defense method metadata concerning results of running the defense methods at the nodes, analyzing the defense method metadata, and based on the analyzing, allocating the defense methods across the nodes. The defense methods may be configured to defend against a model inversion attack.

Claims (30)

1 . A method, comprising:

allocating defense methods, concerning a model inversion attack, to nodes of a federation according to respective resources available at the nodes, and the allocating comprises:

collecting node resource metadata, for each of the nodes, for K federation rounds until a minimum number of nodes is reached for defense method metadata collection;

based on the node resource metadata, performing a constrained resource optimization method that identifies a respective set of defense methods for allocation to each of the nodes, and one of the defense methods is a gradient compression defense;

providing a respective one of the sets of defense methods to each of the nodes;

testing the nodes by causing the respective sets of defense methods to be run at the nodes with respect to respective instances of a model running at the nodes;

collecting defense method metadata concerning results of running the defense methods at the nodes;

analyzing the defense method metadata; and

based on the analyzing, allocating the defense methods across the nodes.

2 . The method as recited in claim 1 , wherein the defense method metadata comprises a quality metric that indicates how well the defense methods performed at the nodes with respect to the model inversion attack.

3 . The method as recited in claim 1 , wherein the defense methods are only allocated to the nodes that have adequate resources available to run the defense methods.

4 . The method as recited in claim 1 , wherein the analyzing comprises applying, to the defense method metadata, a constrained optimization method comprising an objective function that comprises a sum of two functions, wherein the two functions are (1) an average number of the defense methods allocated to each node, and (2) an average number of the nodes allocated to each of the defense methods.

5 . The method as recited in claim 1 , wherein the analyzing of the defense method metadata is performed automatically.

6 . The method as recited in claim 1 , wherein the federation is an element of a heterogeneous federated learning environment.

7 . The method as recited in claim 1 , wherein, given one or more constraints, best ones of the defense methods are allocated across most of the nodes.

8 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

allocating defense methods, concerning a model inversion attack, to nodes of a federation according to respective resources available at the nodes, and the allocating comprises:

collecting node resource metadata, for each of the nodes, for K federation rounds until a minimum number of nodes is reached for defense method metadata collection;

based on the node resource metadata, performing a constrained resource optimization method that identifies a respective set of defense methods for allocation to each of the nodes, and one of the defense methods is a gradient compression defense;

providing a respective one of the sets of defense methods to each of the nodes;

testing the nodes by causing the respective sets of defense methods to be run at the nodes with respect to respective instances of a model running at the nodes;

collecting defense method metadata concerning results of running the defense methods at the nodes;

analyzing the defense method metadata; and

based on the analyzing, allocating the defense methods across the nodes.

9 . The non-transitory storage medium as recited in claim 8 , wherein the defense method metadata comprises a quality metric that indicates how well the defense methods performed at the nodes with respect to the model inversion attack.

10 . The non-transitory storage medium as recited in claim 8 , wherein the defense methods are only allocated to the nodes that have adequate resources available to run the defense methods.

11 . The non-transitory storage medium as recited in claim 8 , wherein the analyzing comprises applying, to the defense method metadata, a constrained optimization method comprising an objective function that comprises a sum of two functions, wherein the two functions are (1) an average number of the defense methods allocated to each node, and (2) an average number of the nodes allocated to each of the defense methods.

12 . The non-transitory storage medium as recited in claim 8 , wherein the analyzing of the defense method metadata is performed automatically.

13 . The non-transitory storage medium as recited in claim 8 , wherein the federation is an element of a heterogeneous federated learning environment.

14 . The non-transitory storage medium as recited in claim 8 , wherein, given one or more constraints, best ones of the defense methods are allocated across most of the nodes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2024
From: DA SILVA, PABLO NASCIMENTO; MAIA, ISABELLA COSTA; PALATNIK DE SOUSA, IAM; CHAGAS, EDUARDA TATIANE CAETANO; MORAN, MAIRA BEATRIZ HERNANDEZ; FERREIRA, PAULO ABELHA
To: DELL PRODUCTS L.P.
Reel/Frame 067367/0335 →
Continuity (1)
Related Publication 20250330483A1 · Oct 23, 2025
References Cited (16)
US 12400031B2 · Arora · 2025 [cited by examiner]
US 20200082097A1 · Poliakov · 2020 [cited by examiner]
US 20210019399A1 · Miller · 2021 [cited by examiner]
US 20210051169A1 · Karame · 2021 [cited by examiner]
US 20210243204A1 · Taylor · 2021 [cited by examiner]
US 20210383280A1 · Shaloudegi · 2021 [cited by examiner]
US 20230196121A1 · Song · 2023 [cited by examiner]
US 20230229786A1 · Eloul · 2023 [cited by examiner]
US 20230308465A1 · Alroobaea · 2023 [cited by examiner]
US 20230370491A1 · Crabtree · 2023 [cited by examiner]
US 20240144029A1 · Feng · 2024 [cited by examiner]
US 20240413969A1 · d'Aliberti · 2024 [cited by examiner]
US 20250094571A1 · Taghia · 2025 [cited by examiner]
US 20250245519A1 · Maia · 2025 [cited by examiner]
Ligeng Zhu, Zhijian Liu, and Song Han. Deep leakage from gradients. In Advances in Neural Information Processing Systems, 2019. [cited by applicant]
Jonas Geiping, Hartmut Bauermeister, Hannah Droge, and Michael Moeller. Inverting gradients—how easy is it to break privacy in federated learning? In Advances in Neural Information Processing Systems, 2020. [cited by applicant]