arXiv:2410.19548cs.LG2024-10被引 3

通过数据蒸馏实现最小化知识共享,保护联邦学习中的用户隐私。

Privacy-Preserving Federated Learning via Dataset Distillation

  • 采用本地-全局数据蒸馏策略减少上传知识量
  • 在保持高模型准确率的同时显著提升隐私防护能力
  • 适合注重隐私保护的联邦学习应用场景

联邦学习(FL)使用户可共享知识而非原始数据来训练高精度模型。然而,在训练过程中,用户失去了对所分享知识的控制,引发严重数据隐私问题。我们认为,用户仅需共享完成训练任务所需的必要知识即可获得高性能模型。但现有方法无法根据用户意愿在联邦训练中最小化共享内容。本文提出FLiP,旨在将最小权限原则(PoLP)引入联邦学习训练过程。其核心设计是通过本地-全局数据蒸馏机制对训练数据进行精细信息压缩。我们通过属性推断和成员推断攻击评估隐私性能。大量实验表明,FLiP在模型准确率与隐私保护之间取得了良好平衡。

原文摘要 · Abstract (English)

Federated Learning (FL) allows users to share knowledge instead of raw data to train a model with high accuracy. Unfortunately, during the training, users lose control over the knowledge shared, which causes serious data privacy issues. We hold that users are only willing and need to share the essential knowledge to the training task to obtain the FL model with high accuracy. However, existing efforts cannot help users minimize the shared knowledge according to the user intention in the FL training procedure. This work proposes FLiP, which aims to bring the principle of least privilege (PoLP) to FL training. The key design of FLiP is applying elaborate information reduction on the training data through a local-global dataset distillation design. We measure the privacy performance through attribute inference and membership inference attacks. Extensive experiments show that FLiP strikes a good balance between model accuracy and privacy protection.

联邦学习隐私保护数据蒸馏

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。