arXiv:2501.05053cs.CRcs.AI2025-01被引 47

TAPFed提升联邦学习隐私性,抗住恶意聚合器的梯度泄露攻击。

TAPFed: Threshold Secure Aggregation for Privacy-Preserving Federated Learning

  • 用阈值功能加密实现多聚合器安全聚合,容错部分恶意节点。
  • 模型精度与顶尖方案相当,通信开销降低29%-45%。
  • 可防御当前主流推理攻击,适合高隐私需求场景。

联邦学习通过多方协作训练模型而不暴露原始数据来增强隐私。然而,现有研究指出传统联邦学习平台因梯度交换存在隐私泄露风险。为实现真正隐私保护的联邦学习,集成安全聚合机制至关重要。但现有方案易受近期提出的解聚攻击影响。本文提出TAPFed,在存在多个去中心化聚合器且部分为恶意方的场景下,实现隐私保护联邦学习。TAPFed采用新型阈值功能加密方案,可在容忍一定数量恶意聚合器的同时保障安全与隐私。我们对TAPFed进行了形式化安全与隐私分析,并在实验中对比多种基线。结果表明,TAPFed在模型质量上与最先进方法相当,同时在不同训练场景下通信开销减少29%-45%。最重要的是,其能有效防御由好奇聚合器引发的最新推理攻击,而多数现有方法对此无能为力。

原文摘要 · Abstract (English)

Federated learning is a computing paradigm that enhances privacy by enabling multiple parties to collaboratively train a machine learning model without revealing personal data. However, current research indicates that traditional federated learning platforms are unable to ensure privacy due to privacy leaks caused by the interchange of gradients. To achieve privacy-preserving federated learning, integrating secure aggregation mechanisms is essential. Unfortunately, existing solutions are vulnerable to recently demonstrated inference attacks such as the disaggregation attack. This paper proposes TAPFed, an approach for achieving privacy-preserving federated learning in the context of multiple decentralized aggregators with malicious actors. TAPFed uses a proposed threshold functional encryption scheme and allows for a certain number of malicious aggregators while maintaining security and privacy. We provide formal security and privacy analyses of TAPFed and compare it to various baselines through experimental evaluation. Our results show that TAPFed offers equivalent performance in terms of model quality compared to state-of-the-art approaches while reducing transmission overhead by 29%-45% across different model training scenarios. Most importantly, TAPFed can defend against recently demonstrated inference attacks caused by curious aggregators, which the majority of existing approaches are susceptible to.

联邦学习隐私保护安全聚合加密

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。