利用无线信道噪声实现联邦微调的差分隐私保护。
Federated Low-Rank Adaptation with Differential Privacy over Wireless Networks
- 用无线上传噪声天然实现差分隐私,无需额外加噪。
- 仅更新低秩矩阵之一,降低噪声放大效应,提升收敛性。
- 适合医疗、金融等对隐私要求高的边缘计算场景。
在分布式边缘设备上微调大型预训练基础模型面临显著的计算和隐私挑战。联邦微调(FedFT)通过不共享原始数据实现协同训练,缓解部分隐私问题。为减轻资源受限设备的计算负担,结合低秩适配(LoRA)与联邦学习可实现参数高效微调。此外,分裂式FedFT架构将基础模型分置于边缘设备与中心服务器,减少单个设备的完整模型部署需求。然而,联邦微调中仍存在隐私窃听攻击风险,尤其在医疗、金融等敏感领域。本文提出一种基于无线网络的分裂式联邦微调框架,利用上行传输中的固有无线信道噪声实现差分隐私(DP)保障,无需添加额外人工噪声。我们研究了无线噪声对收敛性能的影响,并证明仅对其中一个低秩矩阵进行差分隐私更新,即可有效缓解噪声放大效应。仿真结果表明,在严格隐私预算下,该方法相比基线方法获得更高准确率。
原文摘要 · Abstract (English)
Fine-tuning large pre-trained foundation models (FMs) on distributed edge devices presents considerable computational and privacy challenges. Federated fine-tuning (FedFT) mitigates some privacy issues by facilitating collaborative model training without the need to share raw data. To lessen the computational burden on resource-limited devices, combining low-rank adaptation (LoRA) with federated learning enables parameter-efficient fine-tuning. Additionally, the split FedFT architecture partitions an FM between edge devices and a central server, reducing the necessity for complete model deployment on individual devices. However, the risk of privacy eavesdropping attacks in FedFT remains a concern, particularly in sensitive areas such as healthcare and finance. In this paper, we propose a split FedFT framework with differential privacy (DP) over wireless networks, where the inherent wireless channel noise in the uplink transmission is utilized to achieve DP guarantees without adding an extra artificial noise. We shall investigate the impact of the wireless noise on convergence performance of the proposed framework. We will also show that by updating only one of the low-rank matrices in the split FedFT with DP, the proposed method can mitigate the noise amplification effect. Simulation results will demonstrate that the proposed framework achieves higher accuracy under strict privacy budgets compared to baseline methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。