提出FinP框架,让联邦学习中每个人的隐私风险更公平。
FinP: Fairness-in-Privacy in Federated Learning by Addressing Disparities in Privacy Risk
- 用动态加权和正则化,降低敏感用户被攻击的风险
- 在多个数据集上将隐私暴露差异降低57.14%
- 既保护隐私公平,又几乎不损失模型性能
联邦学习虽减少数据集中风险,但隐私保护并不均等,尤其对行为或属性异常的个体更易受源推断攻击。针对这一问题,本文提出FinP框架,通过服务器端自适应聚合与客户端正则化相结合,缓解隐私风险不公。该方法动态调整各客户端贡献权重,并抑制局部过拟合导致的数据记忆。在FEMNIST、HAR和CIFAR-10上的实验表明,FinP有效降低隐私暴露差异,最大降幅达57.14%,同时保持模型性能仅比标准联邦基线下降±1.75%。结果证明,强隐私公平性无需牺牲任务性能。
原文摘要 · Abstract (English)
Federated Learning (FL) inherently mitigates mass data centralization risks; however, its privacy protections are not equally distributed - leaving vulnerable individuals disproportionately exposed to sophisticated privacy attacks. Crucially, statistical heterogeneity in human-centric FL environments often results in an inequitable distribution of privacy risks, particularly affecting those whose sensitive attributes or behaviors make them outliers. To address this critical gap, we introduce FinP, a novel framework designed to formalize and enforce fairness-in-privacy by mitigating disproportionate client vulnerability to Source Inference Attacks (SIA). FinP operationalizes a two-pronged defense strategy that tackles both the symptoms and root causes of privacy disparity, ensuring that no group of clients bears an excessive privacy burden. It combines a server-side adaptive aggregation mechanism, which dynamically weights client contributions based on their estimated privacy risk, with a client-side regularization technique to curb localized overfitting that drives unique data memorization. Extensive empirical evaluations on FEMNIST, Human Activity Recognition (HAR), and CIFAR-10 datasets demonstrate that FinP effectively aligns privacy fairness with primary task utility. Notably, FinP successfully mitigates SIA risks and reduces disparities in privacy exposure, establishing that strong fairness-in-privacy guarantees need not compromise model utility. Ultimately, FinP establishes equitable privacy protections by reducing vulnerability disparities by up to 57.14%, while preserving global model utility within a marginal +/- 1.75% of standard federated baselines.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。