Privacy-Preserving Agentic AI: Federated Learning, Differential Privacy, and Secure Multi-Agent Coordination
Authors
Department of Computer Science, Babcock University, Ilisan Remo, Nigeria (Nigeria)
Department of Computer Science, Babcock University, Ilisan Remo, Nigeria (Nigeria)
Department of Computer Science, Babcock University, Ilisan Remo, Nigeria (Nigeria)
Department of Computer Science, Babcock University, Ilisan Remo, Nigeria (Nigeria)
Department of Computer Science, Babcock University, Ilisan Remo, Nigeria (Nigeria)
Department of Computer Science, Babcock University, Ilisan Remo, Nigeria (Nigeria)
Department of Computer Science, Babcock University, Ilisan Remo, Nigeria (Nigeria)
Department of Computer Science, Babcock University, Ilisan Remo, Nigeria (Nigeria)
Article Information
DOI: 10.51244/IJRSI.2026.1304000155
Subject Category: Artificial Intelligence
Volume/Issue: 13/4 | Page No: 1821-1834
Publication Timeline
Submitted: 2026-04-06
Accepted: 2026-04-11
Published: 2026-05-09
Abstract
The proliferation of autonomous agentic artificial intelligence systems necessitates robust privacy-preserving mechanisms to facilitate secure collaboration in distributed environments. This systematic review investigates the synergistic integration of federated learning (FL), differential privacy (DP), and secure multi-agent coordination in agentic AI systems. Through a comprehensive analysis guided by the PRISMA methodology, we examine how FL enables decentralized model training while preserving data locality, and how DP fortifies these systems against privacy inference attacks through controlled noise injection. Our investigation reveals critical security vulnerabilities including adversarial poisoning and backdoor attacks, while identifying emerging cryptographic solutions such as homomorphic encryption and secure multiparty computation. The findings demonstrate that the convergence of these technologies provides a foundational framework for privacy-respecting autonomous AI systems, though significant challenges remain in scalability and real-world deployment.
Keywords
Agentic artificial intelligence, federated learning, differential privacy, multi-agent systems, privacy preservation, secure coordination
Downloads
References
1. M. Wooldridge, An Introduction to MultiAgent Systems, 2nd ed. Chichester, UK: John Wiley & Sons, 2009. [Google Scholar] [Crossref]
2. Q. Li, Y. Diao, Q. Chen, and B. He, "Federated learning on non-IID data silos: An experimental study," in Proc. IEEE 38th Int. Conf. Data Eng. (ICDE), May 2022, pp. 965–978. [Google Scholar] [Crossref]
3. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, [Google Scholar] [Crossref]
4. "Communication-efficient learning of deep networks from decentralized data," in Proc. 20th Int. Conf. Artif. Intell. Stat., vol. 54, Apr. 2017, pp. 1273–1282. [Google Scholar] [Crossref]
5. A. Hard et al., "Federated learning for mobile keyboard prediction," arXiv preprint arXiv:1811.03604, 2018. [Google Scholar] [Crossref]
6. R. Shokri, M. Stronati, C. Song, and V. Shmatikov, "Membership inference attacks against machine learning models," in Proc. IEEE Symp. Security Privacy, May 2017, pp. 3–18. [Google Scholar] [Crossref]
7. M. Fredrikson, S. Jha, and T. Ristenpart, "Model inversion attacks that exploit confidence information and basic countermeasures," in Proc. 22nd ACM SIGSAC Conf. Comput. Commun. Security, Oct. 2015, pp. 1322–1333. [Google Scholar] [Crossref]
8. C. Dwork, "Differential privacy," in Proc. 33rd Int. Colloq. Automata, Languages Programming, vol. 4052, Jul. 2006, pp. 1–12. [Google Scholar] [Crossref]
9. C. Dwork and A. Roth, "The algorithmic foundations of differential privacy," Found. Trends Theor. Comput. Sci., vol. 9, no. 3–4, pp. 211–407, 2014. [Google Scholar] [Crossref]
10. D. Moher, A. Liberati, J. Tetzlaff, and D. G. Altman, "Preferred reporting items for systematic reviews and meta-analyses: The PRISMA statement," PLoS Med., vol. 6, no. 7, pp. e1000097, 2009. [Google Scholar] [Crossref]
11. P. Kairouz et al., "Advances and open problems in federated learning," Found. Trends Mach. Learn., vol. 14, no. 1–2, pp. 1–210, 2021. [Google Scholar] [Crossref]
12. H. Brendan McMahan and D. Ramage, "Federated learning: Collaborative machine learning without centralized training data," Google AI Blog, Apr. 2017. [Google Scholar] [Crossref]
13. J. Konečný, H. B. McMahan, D. Ramage, and P. Richtárik, "Federated optimization: Distributed machine learning for on-device intelligence," arXiv preprint arXiv:1610.02527, 2016. [Google Scholar] [Crossref]
14. T. Li, A. K. Sahu, A. Talwalkar, and V. Smith, "Federated learning: Challenges, methods, and future directions," IEEE Signal Process. Mag., vol. 37, no. 3, pp. 50–60, 2020. [Google Scholar] [Crossref]
15. Y. Zhao, M. Li, L. Lai, N. Suda, D. Civin, and V. Chandra, "Federated learning with non-IID data," arXiv preprint arXiv:1806.00582, 2018. [Google Scholar] [Crossref]
16. A. Aminifar, M. Shokri, and A. Aminifar, "Privacy-preserving edge federated learning for intelligent mobile-health systems," Future Generation Computer Systems, vol. 161, pp. 625–637, 2024. [Google Scholar] [Crossref]
17. K. Bonawitz et al., "Practical secure aggregation for privacy-preserving machine learning," in Proc. 2017 ACM SIGSAC Conf. Comput. Commun. Security, Oct. 2017, pp. 1175–1191. [Google Scholar] [Crossref]
18. S. Wang et al., "Adaptive federated learning in resource-constrained edge computing systems," IEEE J. Sel. Areas Commun., vol. 37, no. 6, pp. 1205–1221, 2019. [Google Scholar] [Crossref]
19. V. Smith, C.-K. Chiang, M. Sanjabi, and A. Talwalkar, "Federated multi-task learning," in [Google Scholar] [Crossref]
20. Proc. 31st Int. Conf. Neural Inf. Process. Syst., 2017, pp. 4424–4434. [Google Scholar] [Crossref]
21. T. Li, M. Sanjabi, A. Beirami, and V. Smith, "Fair resource allocation in federated learning," in Proc. 8th Int. Conf. Learn. Representations, 2020. [Google Scholar] [Crossref]
22. J. Mills, J. Hu, and G. Min, "Communication-efficient federated learning for wireless edge intelligence in IoT," IEEE Internet Things J., vol. 7, no. 7, pp. 5986–5994, 2020. [Google Scholar] [Crossref]
23. R. Bassily, A. Smith, and A. Thakurta, "Private empirical risk minimization: Efficient algorithms and tight error bounds," in Proc. 55th IEEE FOCS, 2014, pp. 464–473. [Google Scholar] [Crossref]
24. I. Mironov, "Rényi differential privacy," in Proc. 30th IEEE Computer Security Foundations Symposium, 2017, pp. 263–275. [Google Scholar] [Crossref]
25. F. McSherry and K. Talwar, "Mechanism design via differential privacy," in Proc. 48th IEEE Symp. Found. Comput. Sci., 2007, pp. 94–103. [Google Scholar] [Crossref]
26. K. Wei et al., "Federated learning with differential privacy: Algorithms and performance analysis," IEEE Trans. Inf. Forensics Security, vol. 15, pp. 3454–3469, 2020. [Google Scholar] [Crossref]
27. N. Papernot et al., "Semi-supervised knowledge transfer for deep learning from private training data," in Proc. 5th Int. Conf. Learn. Representations, 2017. [Google Scholar] [Crossref]
28. A. Alabdulatif, "GuardianAI: Privacy-preserving federated anomaly detection with differential privacy," Array, vol. 26, 2025. [Google Scholar] [Crossref]
29. M. Abadi et al., "Deep learning with differential privacy," in Proc. 2016 ACM SIGSAC Conf. Comput. Commun. Security, pp. 308–318. [Google Scholar] [Crossref]
30. A. Triastcyn and B. Faltings, "Federated learning with Bayesian differential privacy," in Proc. IEEE Int. Conf. Big Data, 2019, pp. 2587–2596. [Google Scholar] [Crossref]
31. R. Bassily, "Linear queries estimation with local differential privacy," in Proc. AISTATS, 2019, pp. 721–729. [Google Scholar] [Crossref]
32. L. Lyu, H. Yu, and Q. Yang, "Threats to federated learning: A survey," arXiv preprint arXiv:2003.02133, 2020. [Google Scholar] [Crossref]
33. M. Jagielski et al., "Manipulating machine learning: Poisoning attacks and countermeasures for regression learning," in Proc. 2018 IEEE Symp. Security Privacy, pp. 19–35. [Google Scholar] [Crossref]
34. V. Tolpegin, S. Truex, M. E. Gursoy, and L. Liu, "Data poisoning attacks against federated learning systems," in Proc. 25th Eur. Symp. Res. Comput. Security, 2020, pp. 480–501. [Google Scholar] [Crossref]
35. A. N. Bhagoji, S. Chakraborty, P. Mittal, and S. Calo, "Analyzing federated learning through an adversarial lens," in Proc. 36th Int. Conf. Mach. Learn., 2019, pp. 634–643. [Google Scholar] [Crossref]
36. L. Zhu, Z. Liu, and S. Han, "Deep leakage from gradients," in Proc. 33rd Int. Conf. Neural Inf. Process. Syst., 2019, pp. 14774–14784. [Google Scholar] [Crossref]
37. J. Geiping et al., "Inverting gradients: How easy is it to break privacy in federated learning?" in Proc. 34th Int. Conf. Neural Inf. Process. Syst., 2020, pp. 16937–16947. [Google Scholar] [Crossref]
38. J. R. Douceur, "The Sybil attack," in Proc. 1st Int. Workshop Peer-to-Peer Syst., 2002, pp. 251–260. [Google Scholar] [Crossref]
39. C. Fung, C. J. Yoon, and I. Beschastnikh, "Mitigating Sybil attacks in federated learning," arXiv preprint arXiv:1808.04866, 2018. [Google Scholar] [Crossref]
40. J. Zhang et al., "Poisoning attack in federated learning using generative adversarial nets," in [Google Scholar] [Crossref]
41. Proc. 18th IEEE Int. Conf. Trust, Security Privacy Comput. Commun., 2019, pp. 374–380. [Google Scholar] [Crossref]
42. B. Zhao, K. R. Mopuri, and H. Bilen, "iDLG: Improved deep leakage from gradients," arXiv preprint arXiv:2001.02610, 2020. [Google Scholar] [Crossref]
43. C. Gentry, "Fully homomorphic encryption using ideal lattices," in Proc. 41st ACM Symp. Theory Comput., 2009, pp. 169–178. [Google Scholar] [Crossref]
44. J. Wang et al., "FLASHE: Additively symmetric homomorphic encryption for cross-silo federated learning," arXiv preprint arXiv:2109.00675, 2021. [Google Scholar] [Crossref]
45. O. Goldreich, S. Micali, and A. Wigderson, "How to play any mental game," in Proc. 19th Annu. ACM Symp. Theory Comput., 1987, pp. 218–229. [Google Scholar] [Crossref]
46. A. Shamir, "How to share a secret," Commun. ACM, vol. 22, no. 11, pp. 612–613, 1979. [Google Scholar] [Crossref]
47. P. Blanchard et al., "Machine learning with adversaries: Byzantine tolerant gradient descent," in Proc. 31st Int. Conf. Neural Inf. Process. Syst., 2017, pp. 119–129. [Google Scholar] [Crossref]
48. D. Yin et al., "Byzantine-robust distributed learning: Towards optimal statistical rates," in [Google Scholar] [Crossref]
49. Proc. 35th Int. Conf. Mach. Learn., 2018, pp. 5650–5659. [Google Scholar] [Crossref]
50. A. Khraisat et al., "Securing federated learning: A defense strategy against targeted data poisoning attack," Discover Internet of Things, vol. 1, article 8, 2021. [Google Scholar] [Crossref]
51. J. Kang et al., "Incentive mechanism for reliable federated learning: A joint optimization approach to combining reputation and contract theory," IEEE Internet Things J., vol. 6, no. 6, pp. 10700–10714, 2019. [Google Scholar] [Crossref]
52. Y. Lu et al., "Blockchain and federated learning for privacy-preserved data sharing in industrial IoT," IEEE Trans. Ind. Inform., vol. 16, no. 6, pp. 4177–4186, 2020. [Google Scholar] [Crossref]
53. F. Mo et al., "PPFL: Privacy-preserving federated learning with trusted execution environments," in Proc. 27th Annu. Int. Conf. Mobile Comput. Networking, 2021, pp. 94–108. [Google Scholar] [Crossref]
54. S. Han et al., "FedSecurity: Benchmarking Attacks and Defenses in Federated Learning and Federated LLMs," arXiv preprint arXiv:2306.04959, 2023. [Google Scholar] [Crossref]
55. J. So, B. Güler, and A. S. Avestimehr, "Turbo-aggregate: Breaking the quadratic aggregation barrier in secure federated learning," IEEE J. Sel. Areas Inf. Theory, vol. 2, no. 1, [Google Scholar] [Crossref]
56. pp. 479–489, 2021. [Google Scholar] [Crossref]
57. H. Wang et al., "ATOMO: Communication-efficient learning via atomic sparsification," in [Google Scholar] [Crossref]
58. Proc. 32nd Int. Conf. Neural Inf. Process. Syst., 2018, pp. 9850–9861. [Google Scholar] [Crossref]
59. T. Nishio and R. Yonetani, "Client selection for federated learning with heterogeneous resources in mobile edge," in Proc. IEEE Int. Conf. Commun., 2019. [Google Scholar] [Crossref]
60. L. Lyu et al., "Privacy and robustness in federated learning: Attacks and defenses," IEEE Trans. Neural Netw. Learn. Syst., vol. 33, no. 12, pp. 8326–8340, 2022. [Google Scholar] [Crossref]
61. J. Wang et al., "Personalized federated learning with Moreau envelopes," in Proc. 34th Int. Conf. Neural Inf. Process. Syst., 2020, pp. 21394–21405. [Google Scholar] [Crossref]
62. A. Fallah, A. Mokhtari, and A. Ozdaglar, "Personalized federated learning: A meta-learning approach," in Proc. 34th Int. Conf. Neural Inf. Process. Syst., 2020, pp. 10516–10528. [Google Scholar] [Crossref]
63. F. Hanzely et al., "Federated learning of a mixture of global and local models," arXiv preprint arXiv:2002.05516, 2020. [Google Scholar] [Crossref]
64. Y. Liu et al., "FedVision: An online visual object detection platform powered by federated learning," in Proc. AAAI Conf. Artif. Intell., vol. 34, no. 08, Apr. 2020, pp. 13172–13179. [Google Scholar] [Crossref]
65. Y. Mansour et al., "Three approaches for personalization with applications to federated learning," arXiv preprint arXiv:2002.10619, 2020. [Google Scholar] [Crossref]
66. A. Vaswani et al., "Attention is all you need," in Proc. 31st Int. Conf. Neural Inf. Process. Syst., 2017, pp. 5998–6008. [Google Scholar] [Crossref]
67. Y. Chen et al., "Privacy preserving support vector machine based on federated learning for distributed IoT-enabled data analysis," Computational Intelligence, vol. 40, no. 2, pp. 24, 2024. [Google Scholar] [Crossref]
68. J. Xu et al., "Federated learning for healthcare informatics," J. Healthcare Inform. Res., vol. 5, no. 1, pp. 1–19, 2021. [Google Scholar] [Crossref]
69. S. Truex et al., "A hybrid approach to privacy-preserving federated learning," in Proc. 12th ACM Workshop Artif. Intell. Security, 2019, pp. 1–11. [Google Scholar] [Crossref]
70. B. Gu et al., "Privacy-preserving asynchronous vertical federated learning algorithms for multiparty collaborative learning," IEEE Transactions on Neural Networks and Learning Systems, vol. 33, no. 11, pp. 6103–6115, 2022. [Google Scholar] [Crossref]
71. A. Shamsabadi et al., "ColorFool: Semantic adversarial colorization," in Proc. IEEE Conf. Comput. Vision Pattern Recognit., 2020, pp. 1151–1160. [Google Scholar] [Crossref]
72. H. Xie et al., "Secure multi-party computation for federated learning," in Proc. 2020 IEEE Int. Conf. Commun., 2020, pp. 1–6. [Google Scholar] [Crossref]
73. Y. Aono et al., "Privacy-preserving deep learning via additively homomorphic encryption," [Google Scholar] [Crossref]
74. IEEE Trans. Inf. Forensics Security, vol. 13, no. 5, pp. 1333–1345, 2018. [Google Scholar] [Crossref]
75. A. Ghosh et al., "Privacy-enhancing technologies for AI: A review of technical and policy considerations," AI Ethics, vol. 1, no. 3, pp. 215–231, 2021. [Google Scholar] [Crossref]
76. H. Li et al., "FedSA: Secure and efficient federated learning with stochastic aggregation," [Google Scholar] [Crossref]
77. ACM Trans. Priv. Secur., vol. 25, no. 2, pp. 1–27, 2022. [Google Scholar] [Crossref]
78. M. Nasr et al., "Comprehensive privacy analysis of deep learning: From membership inference to model inversion," IEEE Trans. Dependable Secure Comput., vol. 19, no. 1, pp. 419–434, 2022. [Google Scholar] [Crossref]
79. J. Xu et al., "Resource-efficient federated learning: Techniques and future research directions," ACM Comput. Surv., vol. 55, no. 3, pp. 1–36, 2023. [Google Scholar] [Crossref]
80. T. Wang and Y. Yang, "Multi-agent deep reinforcement learning for privacy-preserving coordination," in Proc. AAAI Conf. Artif. Intell., 2022. [Google Scholar] [Crossref]
81. E. Erlingsson et al., "Amortized privacy for practical differentially private learning," in Proc. 2020 ACM SIGSAC Conf. Comput. Commun. Security, pp. 1–14. [Google Scholar] [Crossref]
82. R. Cramer et al., "Secure computation and zero-knowledge proofs: From theory to practice," Commun. ACM, vol. 64, no. 1, pp. 110–119, 2021. [Google Scholar] [Crossref]
83. T. T. Nguyen et al., "A survey on federated learning attack and defense techniques," IEEE Internet Things J., vol. 9, no. 1, pp. 547–568, 2022. [Google Scholar] [Crossref]
84. S. K. Thapa et al., "Survey on trustworthiness in federated learning," ACM Comput. Surv., [Google Scholar] [Crossref]
85. vol. 54, no. 11, pp. 1–37, 2022. [Google Scholar] [Crossref]
86. Y. Jiang et al., "Communication-efficient FL with adaptive model compression," in Proc. NeurIPS, 2021. [Google Scholar] [Crossref]
87. L. Fan, "Outlier detection for robust federated learning," Pattern Recognit. Lett., vol. 154, [Google Scholar] [Crossref]
88. pp. 80–87, 2022. [Google Scholar] [Crossref]
89. X. Zheng et al., "Enhancing privacy with blockchain-integrated federated learning," Future Gener. Comput. Syst., vol. 125, pp. 136–148, 2021. [Google Scholar] [Crossref]
90. S. H. Low et al., "Privacy amplification by iteration," in Proc. COLT, 2021. [Google Scholar] [Crossref]
91. J. Kim et al., "FedMix: Addressing data heterogeneity in FL via local mixing," in Proc. 38th ICML, 2021. [Google Scholar] [Crossref]
92. A. Oliva et al., "Fairness in federated learning: Existing solutions and open challenges," [Google Scholar] [Crossref]
93. ACM Comput. Surv., vol. 56, no. 1, pp. 1–27, 2023. [Google Scholar] [Crossref]
94. D. Arief et al., "Self-sovereign identity meets federated AI: A privacy-aware approach," [Google Scholar] [Crossref]
95. Blockchain Res. Appl., vol. 3, no. 4, pp. 100213, 2022. [Google Scholar] [Crossref]
96. K. Hsieh et al., "Group-wise differential privacy: Scalable protection for FL systems," in [Google Scholar] [Crossref]
97. Proc. 2022 IEEE S&P. [Google Scholar] [Crossref]
98. P. Jain and R. Williams, "Differential privacy in multi-agent optimization: Guarantees and applications," in Proc. 2022 NeurIPS. [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- The Role of Artificial Intelligence in Revolutionizing Library Services in Nairobi: Ethical Implications and Future Trends in User Interaction
- ESPYREAL: A Mobile Based Multi-Currency Identifier for Visually Impaired Individuals Using Convolutional Neural Network
- Comparative Analysis of AI-Driven IoT-Based Smart Agriculture Platforms with Blockchain-Enabled Marketplaces
- AI-Based Dish Recommender System for Reducing Fruit Waste through Spoilage Detection and Ripeness Assessment
- SEA-TALK: An AI-Powered Voice Translator and Southeast Asian Dialects Recognition