arXiv:2502.04601cs.CRcs.LG2025-02

提出安全异步联邦学习框架,用可信执行环境与梯度混淆防护隐私泄露。

LATTEO: A Framework to Support Learning Asynchronously Tempered with Trusted Execution and Obfuscation

  • 结合可信执行环境与梯度混淆,保护异步联邦学习中的隐私。
  • 数据重建攻击的结构相似性降低85%,重构误差提升400%。
  • 新认证机制支持动态参与,延迟比RA-TLS低1500%且无额外开销。

联邦学习(FL)的隐私漏洞主要源于梯度泄露,现有防御多针对同步系统,忽视了异步场景。本文首次通过新型数据重建攻击揭示异步FL的隐私风险。为此,提出融合梯度混淆与可信执行环境(TEEs)的隐私保护框架,实现边缘侧安全聚合。为克服传统环信验证局限,引入基于多权威属性加密的数据中心化认证机制,使客户端可隐式验证TEE聚合服务,有效应对按需参与与连接规模扩展。梯度混淆使数据重建的结构相似性下降85%,重构误差提高400%;框架将验证延迟相比RA-TLS降低1500%,无额外开销。

原文摘要 · Abstract (English)

The privacy vulnerabilities of the federated learning (FL) paradigm, primarily caused by gradient leakage, have prompted the development of various defensive measures. Nonetheless, these solutions have predominantly been crafted for and assessed in the context of synchronous FL systems, with minimal focus on asynchronous FL. This gap arises in part due to the unique challenges posed by the asynchronous setting, such as the lack of coordinated updates, increased variability in client participation, and the potential for more severe privacy risks. These concerns have stymied the adoption of asynchronous FL. In this work, we first demonstrate the privacy vulnerabilities of asynchronous FL through a novel data reconstruction attack that exploits gradient updates to recover sensitive client data. To address these vulnerabilities, we propose a privacy-preserving framework that combines a gradient obfuscation mechanism with Trusted Execution Environments (TEEs) for secure asynchronous FL aggregation at the network edge. To overcome the limitations of conventional enclave attestation, we introduce a novel data-centric attestation mechanism based on Multi-Authority Attribute-Based Encryption. This mechanism enables clients to implicitly verify TEE-based aggregation services, effectively handle on-demand client participation, and scale seamlessly with an increasing number of asynchronous connections. Our gradient obfuscation mechanism reduces the structural similarity index of data reconstruction by 85% and increases reconstruction error by 400%, while our framework improves attestation efficiency by lowering average latency by up to 1500% compared to RA-TLS, without additional overhead.

联邦学习隐私保护可信执行异步系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。