用抗量子加密增强联邦学习模型更新的安全性
Enhancing Quantum Security over Federated Learning via Post-Quantum Cryptography
- 采用三种NIST标准抗量子签名算法保护联邦学习中的模型更新
- 实验证明Dilithium在效率上优于FALCON和SPHINCS+
- 适合关注隐私与量子安全的机器学习系统设计者
联邦学习(FL)已成为在边缘设备上部署机器学习模型的标准方法,其中私有训练数据分布在各客户端,通过聚合每个客户端本地计算的更新来学习共享模型。尽管该范式通过仅在每轮训练结束时传输更新提升了通信效率,但传输的模型更新仍易受恶意篡改,威胁全局模型完整性。虽然现有数字签名算法可保护这些通信更新,但在大规模量子计算时代无法确保量子安全。幸运的是,多种抗量子密码算法已被开发,尤其是三种NIST标准化算法——Dilithium、FALCON和SPHINCS+。本文实证研究了这三种NIST标准化抗量子密码算法在联邦学习流程中的影响,涵盖多种模型、任务及联邦学习设置。结果表明,Dilithium在联邦学习中作为数字签名的抗量子算法表现最高效。此外,我们深入讨论了研究发现的含义及未来研究方向。
原文摘要 · Abstract (English)
Federated learning (FL) has become one of the standard approaches for deploying machine learning models on edge devices, where private training data are distributed across clients, and a shared model is learned by aggregating locally computed updates from each client. While this paradigm enhances communication efficiency by only requiring updates at the end of each training epoch, the transmitted model updates remain vulnerable to malicious tampering, posing risks to the integrity of the global model. Although current digital signature algorithms can protect these communicated model updates, they fail to ensure quantum security in the era of large-scale quantum computing. Fortunately, various post-quantum cryptography algorithms have been developed to address this vulnerability, especially the three NIST-standardized algorithms - Dilithium, FALCON, and SPHINCS+. In this work, we empirically investigate the impact of these three NIST-standardized PQC algorithms for digital signatures within the FL procedure, covering a wide range of models, tasks, and FL settings. Our results indicate that Dilithium stands out as the most efficient PQC algorithm for digital signature in federated learning. Additionally, we offer an in-depth discussion of the implications of our findings and potential directions for future research.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。