arXiv:2501.04409cs.LG2025-01

提出无损隐私聚合方法LPPA,保护联邦学习中梯度传输隐私且不降低模型精度。

Lossless Privacy-Preserving Aggregation for Decentralized Federated Learning

  • 通过注入收发噪声差值实现隐私保护,利用邻居随机性增强安全性。
  • 理论证明隐私能力提升√2倍,实验显示比加噪方法平均准确率高14%。
  • 适合注重隐私与精度兼得的去中心化联邦学习场景,如医疗、金融数据协作。

随着敏感数据泛滥,隐私问题日益突出。尽管去中心化联邦学习(DFL)通过邻居间梯度聚合避免直接传输数据,但仍存在梯度泄露风险。现有隐私保护方法在梯度中加噪,要么降低模型预测精度,要么保护效果不佳。本文提出一种新型无损隐私聚合规则LPPA,可在不损失模型预测精度的前提下最大化梯度保护。LPPA巧妙地将发送与接收噪声之间的差异注入传输梯度中,利用各客户端邻居的随机性有效防止数据泄露。基于噪声流守恒理论,所有噪声差值的全局和为零,确保梯度聚合准确无误,模型精度不受影响。理论上证明LPPA的隐私保护能力是加噪方法的√2倍,同时保持与标准DFL聚合相当的模型精度。实验验证了理论结果,LPPA相比加噪方法平均准确率提升14%,并有效保护原始数据,实现无损模型精度。

原文摘要 · Abstract (English)

Privacy concerns arise as sensitive data proliferate. Despite decentralized federated learning (DFL) aggregating gradients from neighbors to avoid direct data transmission, it still poses indirect data leaks from the transmitted gradients. Existing privacy-preserving methods for DFL add noise to gradients. They either diminish the model predictive accuracy or suffer from ineffective gradient protection. In this paper, we propose a novel lossless privacy-preserving aggregation rule named LPPA to enhance gradient protection as much as possible but without loss of DFL model predictive accuracy. LPPA subtly injects the noise difference between the sent and received noise into transmitted gradients for gradient protection. The noise difference incorporates neighbors' randomness for each client, effectively safeguarding against data leaks. LPPA employs the noise flow conservation theory to ensure that the noise impact can be globally eliminated. The global sum of all noise differences remains zero, ensuring that accurate gradient aggregation is unaffected and the model accuracy remains intact. We theoretically prove that the privacy-preserving capacity of LPPA is \sqrt{2} times greater than that of noise addition, while maintaining comparable model accuracy to the standard DFL aggregation without noise injection. Experimental results verify the theoretical findings and show that LPPA achieves a 14% mean improvement in accuracy over noise addition. We also demonstrate the effectiveness of LPPA in protecting raw data and guaranteeing lossless model accuracy.

联邦学习隐私保护无损聚合梯度安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。