提出一种兼顾通信效率与隐私可调的联邦学习机制
Communication-Efficient and Privacy-Adaptable Mechanism for Federated Learning
- 用随机量化实现压缩与差分隐私联合保护
- 在MNIST上比基线模型更准确,且支持隐私等级自定义
- 适合对隐私和通信成本敏感的分布式学习场景
通过联邦学习在去中心化私有数据上训练模型面临通信效率与隐私保护两大挑战。本文在可信聚合器模型下提出新型方法CEPAM,同时实现双重目标。CEPAM采用拒绝采样的通用量化器(RSUQ),其失真等价于预设噪声(如高斯或拉普拉斯噪声),从而联合实现差分隐私与数据压缩。该机制具备隐私可调性,客户端与服务器可根据精度要求灵活定制隐私保护强度。我们理论分析了CEPAM的隐私保障,并通过实验评估其在用户隐私、模型精度间的权衡。在MNIST数据集上的测试表明,CEPAM在保持通信高效的同时,优于基线模型的学习精度。
原文摘要 · Abstract (English)
Training machine learning models on decentralized private data via federated learning (FL) poses two key challenges: communication efficiency and privacy protection. In this work, we address these challenges within the trusted aggregator model by introducing a novel approach called the Communication-Efficient and Privacy-Adaptable Mechanism (CEPAM), achieving both objectives simultaneously. In particular, CEPAM leverages the rejection-sampled universal quantizer (RSUQ), a construction of randomized vector quantizer whose resulting distortion is equivalent to a prescribed noise, such as Gaussian or Laplace noise, enabling joint differential privacy and compression. Our CEPAM provides the additional benefit of privacy adaptability, allowing clients and the server to customize privacy protection based on required accuracy and protection. We theoretically analyze the privacy guarantee of CEPAM and investigate the trade-offs among user privacy and accuracy of CEPAM through experimental evaluations. Moreover, we assess CEPAM's utility performance using MNIST dataset, demonstrating that CEPAM surpasses baseline models in terms of learning accuracy.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。