用动态噪声控制提升联邦学习隐私性,制造过程监测效果超传统方法37%
Privacy-Preserving Federated Learning with Differentially Private Hyperdimensional Computing
- 通过神经符号计算与差分隐私结合,实时监控并按需添加噪声
- 在真实制造监测场景中性能优于主流框架最高37%且保持高精度
- 适合对隐私与持续学习有要求的物联网工业应用
联邦学习(FL)已成为物联网环境中的关键数据隐私保护技术,其通过本地训练模型并仅传输更新来避免原始数据外泄。然而,仍面临模型反演和成员推断攻击等威胁,可能泄露训练数据。尽管差分隐私(DP)常被用于缓解风险,但直接向黑箱模型注入噪声会损害准确率,尤其在动态物联网环境中,持续终身学习导致噪声累积过量。为此,我们提出隐私保护的联邦超维计算框架FedHDPrivacy,融合神经符号计算与差分隐私。该框架主动监测各轮学习的累积噪声,并仅添加满足隐私约束所需的额外噪声。在真实制造加工过程监测应用中,FedHDPrivacy在保持高性能的同时,相较联邦平均(FedAvg)、联邦近似(FedProx)、联邦归一化平均(FedNova)和联邦优化(FedOpt)等标准框架最高提升37%。未来可拓展至多模态数据融合等方向。
原文摘要 · Abstract (English)
Federated Learning (FL) has become a key method for preserving data privacy in Internet of Things (IoT) environments, as it trains Machine Learning (ML) models locally while transmitting only model updates. Despite this design, FL remains susceptible to threats such as model inversion and membership inference attacks, which can reveal private training data. Differential Privacy (DP) techniques are often introduced to mitigate these risks, but simply injecting DP noise into black-box ML models can compromise accuracy, particularly in dynamic IoT contexts, where continuous, lifelong learning leads to excessive noise accumulation. To address this challenge, we propose Federated HyperDimensional computing with Privacy-preserving (FedHDPrivacy), an eXplainable Artificial Intelligence (XAI) framework that integrates neuro-symbolic computing and DP. Unlike conventional approaches, FedHDPrivacy actively monitors the cumulative noise across learning rounds and adds only the additional noise required to satisfy privacy constraints. In a real-world application for monitoring manufacturing machining processes, FedHDPrivacy maintains high performance while surpassing standard FL frameworks - Federated Averaging (FedAvg), Federated Proximal (FedProx), Federated Normalized Averaging (FedNova), and Federated Optimization (FedOpt) - by up to 37%. Looking ahead, FedHDPrivacy offers a promising avenue for further enhancements, such as incorporating multimodal data fusion.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。