GDPR-conform Machine Learning in cross-enterprise environments
Lade...
Datum
Autor:innen
Zeitschriftentitel
ISSN der Zeitschrift
Bandtitel
Verlag
Sonstige Titel
Zusammenfassung
Cross-enterprise Machine Learning (ML) promises substantial utility gains by combining complementary data held by different organizations, yet it faces persistent barriers from data sovereignty requirements, heterogeneous IT landscapes and regulatory constraints such as the EU General Data Protection Regulation (GDPR). Although Federated Learning (FL) mitigates centralized data collection by keeping raw data local, practical deployments remain exposed to indirect leakage via shared model updates (e.g., membership inference or gradient-based reconstruction) and to governance frictions when coordinating training across organizational boundaries. In addition, GDPR obligations go beyond confidentiality and include lifecycle requirements, most prominently the Right to Erasure (Art.~17), which makes post-hoc deletion requests technically challenging once models have been trained on personal data.
This thesis addresses these challenges by designing an integrated, privacy-preserving and GDPR-conform FL stack for execution in federated Data Spaces. First, it contributes FedDScon, an engineering framework that operationalizes FL-capable Data Space infrastructures on top of modern connector technology (with an emphasis on Eclipse Dataspace Connector concepts) and automates essential processes such as asset provisioning, contract negotiation and governed data transfer setup. Second, it develops a layered privacy-by-design toolkit for distributed learning in Data Spaces. Approaches such as DP-LLP and DP-LSTM are proposed, which restrict cross-party communication to differentially private aggregates for time-series learning and the HEX-FL framework, which protects model updates during federated aggregation using CKKS-based (multiparty) homomorphic encryption. Third, it introduces CeMUFl, a certified federated unlearning approach that integrates an unlearning procedure into the FL pipeline and adds a hash-based certification mechanism to make compliance-relevant model versioning verifiable across heterogeneous participants.
Finally, the thesis synthesizes these artifacts into Feder, a modular end-to-end framework that composes the Data Space governance layer (FedDScon), the privacy-preserving training layer (HEX-FL and DP-based methods) and the compliance/lifecycle layer (CeMUFl) into one coherent architecture for regulated, cross-enterprise analytics.
Beschreibung
Inhaltsverzeichnis
Schlagwörter
GDPR, Feder, HEX-FL, CeMUFl, Data Space
Schlagwörter nach RSWK
Föderales Lernen, Maschinelles Lernen, Datenschutz, Personenbezogene Daten, Recht auf Vergessenwerden, Digitale Souveränität
