无线联邦学习中用协作干扰增强隐私,无需客户端加噪。
Providing Differential Privacy for Federated Learning Over Wireless: A Cross-layer Framework
- 通过动态功率控制与协作干扰生成人工噪声提升隐私
- 在非独立同分布数据下仍保持高精度,优于现有方法
- 适用于多种联邦学习框架,适合对隐私要求高的边缘场景
联邦学习(FL)允许边缘设备本地训练数据,但模型更新仍存在隐私泄露风险。针对无线边缘网络的过载空中联邦学习(OTA-FL),本文提出一种物理层设计,通过去中心化的动态功率控制,利用无线信道固有的高斯噪声,并在需要更高隐私时引入协作干扰器(CJ)生成额外人工噪声,以增强差分隐私(DP)。该方案不依赖客户端加噪,可适配各类联邦学习算法(如FedAvg、FedProx),并基于上行重用框架(Upcycled-FL)实现资源高效训练。采用矩量会计法进行隐私分析,对非凸目标函数开展收敛性研究,揭示隐私与准确率间的权衡。数值实验表明,在非独立同分布的FEMNIST数据集上,本方法在同等隐私约束下优于当前最优方案,且协作干扰器显著提升隐私保障能力。
原文摘要 · Abstract (English)
Federated Learning (FL) is a distributed machine learning framework that inherently allows edge devices to maintain their local training data, thus providing some level of privacy. However, FL's model updates still pose a risk of privacy leakage, which must be mitigated. Over-the-air FL (OTA-FL) is an adapted FL design for wireless edge networks that leverages the natural superposition property of the wireless medium. We propose a wireless physical layer (PHY) design for OTA-FL which improves differential privacy (DP) through a decentralized, dynamic power control that utilizes both inherent Gaussian noise in the wireless channel and a cooperative jammer (CJ) for additional artificial noise generation when higher privacy levels are required. Although primarily implemented within the Upcycled-FL framework, where a resource-efficient method with first-order approximations is used at every even iteration to decrease the required information from clients, our power control strategy is applicable to any FL framework, including FedAvg and FedProx as shown in the paper. This adaptation showcases the flexibility and effectiveness of our design across different learning algorithms while maintaining a strong emphasis on privacy. Our design removes the need for client-side artificial noise injection for DP, utilizing a cooperative jammer to enhance privacy without affecting transmission efficiency for higher privacy demands. Privacy analysis is provided using the Moments Accountant method. We perform a convergence analysis for non-convex objectives to tackle heterogeneous data distributions, highlighting the inherent trade-offs between privacy and accuracy. Numerical results show that our approach with various FL algorithms outperforms the state-of-the-art under the same DP conditions on the non-i.i.d. FEMNIST dataset, and highlight the cooperative jammer's effectiveness in ensuring strict privacy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。