GDPR-conform Machine Learning in cross-enterprise environments

dc.contributor.advisorLiebig, Thomas
dc.contributor.authorSachweh, Timon
dc.contributor.refereeJungeblut, Thorsten
dc.date.accepted2026-06-16
dc.date.accessioned2026-07-21T12:30:07Z
dc.date.issued2026
dc.description.abstractCross-enterprise Machine Learning (ML) promises substantial utility gains by combining complementary data held by different organizations, yet it faces persistent barriers from data sovereignty requirements, heterogeneous IT landscapes and regulatory constraints such as the EU General Data Protection Regulation (GDPR). Although Federated Learning (FL) mitigates centralized data collection by keeping raw data local, practical deployments remain exposed to indirect leakage via shared model updates (e.g., membership inference or gradient-based reconstruction) and to governance frictions when coordinating training across organizational boundaries. In addition, GDPR obligations go beyond confidentiality and include lifecycle requirements, most prominently the Right to Erasure (Art.~17), which makes post-hoc deletion requests technically challenging once models have been trained on personal data. This thesis addresses these challenges by designing an integrated, privacy-preserving and GDPR-conform FL stack for execution in federated Data Spaces. First, it contributes FedDScon, an engineering framework that operationalizes FL-capable Data Space infrastructures on top of modern connector technology (with an emphasis on Eclipse Dataspace Connector concepts) and automates essential processes such as asset provisioning, contract negotiation and governed data transfer setup. Second, it develops a layered privacy-by-design toolkit for distributed learning in Data Spaces. Approaches such as DP-LLP and DP-LSTM are proposed, which restrict cross-party communication to differentially private aggregates for time-series learning and the HEX-FL framework, which protects model updates during federated aggregation using CKKS-based (multiparty) homomorphic encryption. Third, it introduces CeMUFl, a certified federated unlearning approach that integrates an unlearning procedure into the FL pipeline and adds a hash-based certification mechanism to make compliance-relevant model versioning verifiable across heterogeneous participants. Finally, the thesis synthesizes these artifacts into Feder, a modular end-to-end framework that composes the Data Space governance layer (FedDScon), the privacy-preserving training layer (HEX-FL and DP-based methods) and the compliance/lifecycle layer (CeMUFl) into one coherent architecture for regulated, cross-enterprise analytics.en
dc.identifier.urihttp://hdl.handle.net/2003/45028
dc.identifier.urihttp://dx.doi.org/10.17877/DE290R-26795
dc.language.isoen
dc.subjectGDPRen
dc.subjectFederde
dc.subjectHEX-FLen
dc.subjectCeMUFlen
dc.subjectData Spaceen
dc.subject.ddc004
dc.subject.rswkFöderales Lernende
dc.subject.rswkMaschinelles Lernende
dc.subject.rswkDatenschutzde
dc.subject.rswkPersonenbezogene Datende
dc.subject.rswkRecht auf Vergessenwerdende
dc.subject.rswkDigitale Souveränitätde
dc.titleGDPR-conform Machine Learning in cross-enterprise environmentsen
dc.typeText
dc.type.publicationtypePhDThesis
dcterms.accessRightsopen access
eldorado.dnb.deposittrue
eldorado.secondarypublicationfalse

Dateien

Originalbündel

Gerade angezeigt 1 - 1 von 1
Lade...
Vorschaubild
Name:
Dissertation_Sachweh.pdf
Größe:
3.93 MB
Format:
Adobe Portable Document Format
Beschreibung:
DNB

Lizenzbündel

Gerade angezeigt 1 - 1 von 1
Lade...
Vorschaubild
Name:
license.txt
Größe:
4.82 KB
Format:
Item-specific license agreed upon to submission
Beschreibung: