Researchers from GATV participate in a new scientific publication linked to the Synthema project

Researchers from the Visual Telecommunications Applications Group (GATV) at the Universidad Politécnica de Madrid have participated in a new scientific publication within the framework of the Synthema project, focused on advanced privacy analysis in distributed machine learning environments.

The work involved the participation of Borja Arroyo Galende, together with Silvia Alba Uribe Mayoral and Federico Álvarez, contributing to the research and scientific dissemination activities carried out within the project.

The publication, titled The Geometry of Privacy: A Two-Stage Analysis of Generative Membership Inference in Federated Learning, addresses privacy challenges in Federated Learning from a structural perspective. Rather than treating membership inference as a single phenomenon, the paper introduces a two-stage decomposition: first, the “survival” of a client’s signal after aggregation and system noise (Signal Survival), and second, the attribution of that signal to private data through generative Membership Inference Attack models (Signal Attribution).

This approach enables the characterization of privacy risk based on the geometry of client contributions, showing that detectability critically depends on the alignment between local updates and the behavior of the global aggregation. In addition, the attribution stage establishes theoretical bounds based on smoothness properties and local path representations, avoiding dependencies on specific model architectures.

The publication represents a significant step forward in the group’s research lines, reinforcing GATV’s participation in international initiatives focused on privacy, distributed artificial intelligence, and generative models applied to real-world scenarios.

These types of contributions strengthen the transfer of research results to the scientific and technological community, fostering collaboration between institutions and supporting the development of more robust methodologies for privacy risk assessment in federated learning systems.

The full article can be accessed at the following link: MDPI Publication