提出分布式矩阵机制,兼顾隐私与模型效果。
DMM: Distributed Matrix Mechanism for Differentially-Private Federated Learning Based on Constant-Overhead Linear Secret Resharing
- 用常量通信开销的密钥重分配协议实现跨轮次隐私值安全传输
- 相比已有方法,模型准确率显著提升且开销几乎不变
- 适合需要高隐私保护的动态用户参与场景
基于中心化差分隐私(DP)的联邦学习(FL)近年来因矩阵机制在实用性上取得显著进步,而基于分布式(更私密)DP 的方案则进展缓慢。本文提出分布式矩阵机制,兼顾分布式 DP 的更强隐私性与矩阵机制带来的更高效用。通过一种新颖的密码学协议,实现不同训练轮次间客户端委员会间敏感值的安全转移,且通信开销恒定。该协议支持联邦学习中用户动态参与,包括中途退出的情况。实验表明,本机制相比现有分布式 DP 方法显著提升了模型效用,同时增加的开销可忽略不计。
原文摘要 · Abstract (English)
Federated Learning (FL) solutions with central Differential Privacy (DP) have seen large improvements in their utility in recent years arising from the matrix mechanism, while FL solutions with distributed (more private) DP have lagged behind. In this work, we introduce the distributed matrix mechanism to achieve the best-of-both-worlds; better privacy of distributed DP and better utility from the matrix mechanism. We accomplish this using a novel cryptographic protocol that securely transfers sensitive values across client committees of different training iterations with constant communication overhead. This protocol accommodates the dynamic participation of users required by FL, including those that may drop out from the computation. We provide experiments which show that our mechanism indeed significantly improves the utility of FL models compared to previous distributed DP mechanisms, with little added overhead.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。