Abstract
Split federated learning protects client data by injecting Gaussian noise into intermediate representations before they are sent to an edge server. When clients run heterogeneous model architectures, their representations differ in sensitivity, yet an unclipped implementation may calibrate every release to one shared surrogate C. We isolate the resulting Sensitivity Gap: the claimed Gaussian-mechanism certificate is not supported when C is not a valid ceiling for every released representation. This is a mechanism-specific calibration failure, not a flaw in differential privacy composition or a lower bound on the mechanism's minimal privacy parameter. We give a round-indexed recalculation of a valid transcript certificate and propose Sensitivity-Aware Budget Allocation (SABA), which quantizes client sensitivities into global, tiered, or per-client calibration profiles. On heterogeneous MLP and Vision Transformer encoders for CIFAR-10 and CIFAR-100, an empirical-input diagnostic and an independent one-sided attack witness decrease by more than 82% with 0.1–0.6 accuracy-point changes. For MLPs, a completed five-seed sweep using per-round spectral-norm ceilings restores the nominal certificate. The empirical study is a controlled proof of concept; only the fixed-state MLP releases supplied with valid spectral ceilings are certified.
Keywords
Illustration
Citation
@article{Quan2026The,
title={The Sensitivity Gap: Privacy Miscalibration in Heterogeneous Split Federated Learning},
author={Minh K. Quan and Pubudu N. Pathirana},
year={2026},
url={https://cspaper.org/openprint/20260808.0001v1},
journal={OpenPrint:20260808.0001v1}
}Version History
| Version | Released Date | Submitter |
|---|---|---|
v1Current | Aug 8, 2026 | Minh Quan |
