让每个用户按自己意愿设定隐私等级,提升联邦学习的隐私与效果平衡。
Federated Learning With Individualized Privacy Through Client Sampling
- 按用户隐私偏好动态调整采样率,实现个性化差分隐私
- 在多个数据集上显著优于统一隐私保护基线
- 适合注重隐私差异化的实际应用场景
随着用户数据收集引发的隐私担忧日益增加,个性化隐私成为平衡隐私保护与模型效用的有前景方案,能够根据用户的个体隐私偏好灵活设置。不同于对所有用户施加统一匿名化程度的做法,该方法允许用户根据自身舒适度选择隐私级别。基于此,我们提出一种在联邦学习中实现个性化差分隐私(IDP)的改进方法,通过客户端采样机制,依据各客户端异构的隐私预算计算其专属采样率,并集成至改进的IDP-FedAvg算法。我们在真实隐私分布及多个数据集上进行了测试,结果表明,该方法显著优于统一差分隐私基线,有效缓解了隐私与性能之间的权衡。相比相关工作中分配不同噪声尺度的SCALE方法,本方法表现更优。然而,在非独立同分布(non-i.i.d.)数据的复杂任务中仍面临挑战,主要源于去中心化设置的限制。
原文摘要 · Abstract (English)
With growing concerns about user data collection, individualized privacy has emerged as a promising solution to balance protection and utility by accounting for diverse user privacy preferences. Instead of enforcing a uniform level of anonymization for all users, this approach allows individuals to choose privacy settings that align with their comfort levels. Building on this idea, we propose an adapted method for enabling Individualized Differential Privacy (IDP) in Federated Learning (FL) by handling clients according to their personal privacy preferences. By extending the SAMPLE algorithm from centralized settings to FL, we calculate client-specific sampling rates based on their heterogeneous privacy budgets and integrate them into a modified IDP-FedAvg algorithm. We test this method under realistic privacy distributions and multiple datasets. The experimental results demonstrate that our approach achieves clear improvements over uniform DP baselines, reducing the trade-off between privacy and utility. Compared to the alternative SCALE method in related work, which assigns differing noise scales to clients, our method performs notably better. However, challenges remain for complex tasks with non-i.i.d. data, primarily stemming from the constraints of the decentralized setting.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。