Federated Learning with Differential Privacy for Cross-Institutional Datasets: A Trade- off Analysis between Model Performance and Data Leakage

Digital Transformation and Technology Dynamics

Mahmuda Begum, Md Rasel Ul Alam, Md. Farhan Islam Alvi

International Islamic University Chittagong; University of the Cumberlands, Kentucky; Jagannath University

Digital Transformation and Technology DynamicsVol. 6, Issue 1July 28, 2026

Download PDF

Abstract

Collaborative machine learning across cross-institutional datasets, such
as multi-hospital Electronic Health Records (EHR) and cross-bank
financial fraud telemetry, is routinely constrained by stringent data
protection mandates (e.g., HIPAA, GDPR) and competitive
confidentiality concerns. While Federated Learning (FL) enables
collaborative training without raw data centralization, standard FL
architectures remain vulnerable to privacy-leaking attacks, including
Membership Inference Attacks (MIA) and model inversion vector
extraction. Integrating Differential Privacy (DP) into FL offers
mathematically bounded privacy guarantees (ε, δ), but injects stochastic
noise into local gradient updates, giving rise to a fundamental trade-off
between model utility (AUC-ROC / F1-Score) and empirical privacy
leakage. This paper presents an empirical trade-off analysis evaluating
DP-FL across cross-institutional healthcare and financial datasets
spanning 12 decentralized nodes over 100 global training rounds. We
rigorously quantify how varying privacy budgets (ε ∈ [0.5, 10.0]) and
gradient clipping thresholds (C ∈ [0.1, 2.0]) influence model

convergence, utility degradation, and vulnerability against state-of-the-
art MIA probes. Empirical results demonstrate that under a strict privacy

budget (ε = 1.0), DP-FL reduces MIA vulnerability by 87.6% (capping
attack accuracy near random guessing at 52.1%) while incurring an

acceptable 4.8% utility drop in healthcare mortality prediction (AUC-
ROC = 0.884 vs. 0.932 non-private FL). To mitigate the noise-utility

penalty, we propose an Adaptive Noise-Decay DP-FL (AND-DPFL)
Engine that dynamically recalibrates noise scale across training epochs,
recovering 68.5% of lost utility while retaining strict privacy bounds (ε
= 1.0, δ = 10−5).

Keywords

Federated Learning (FL)Differential Privacy (DP)Cross-Institutional DatasetsMembership Inference Attacks (MIA)Data LeakagePrivacy-Utility Trade-offHealthcare AIFinancial Fraud Detection

Article Information

Published
July 28, 2026
Journal
Digital Transformation and Technology Dynamics
Volume / Issue
6 / 1
Year
7

Browse

All published articles · Journal archive