arXiv:2503.04054cs.LGcs.CR2025-03

提出隐私保护分组学习新方法,解决多组重叠时信息泄露问题。

Controlled privacy leakage propagation throughout overlapping grouped learning

  • 设计差分隐私分组学习框架,支持跨组重叠的协作训练。
  • 实验证明在保持强隐私的同时,模型性能优于传统联邦学习。
  • 适合关注隐私安全与多方协作的科研人员和工程师。

联邦学习(FL)是协同学习的标准协议,多个参与者在本地数据上训练共享模型,并交换模型更新而非原始数据。由于参与者常按兴趣或隐私政策形成群体,我们考虑一种存在多个可能重叠群体的场景。在此情况下,理解隐私泄露并遵守隐私策略变得复杂。为此,我们提出差分隐私重叠分组学习(DPOGL),在诚实但好奇威胁模型下,为任意两方提供新颖的隐私保障。这些保障量化了两种关键效应:传播延迟——信息通过共用成员仅在时间上延迟向其他组泄露;信息降解——模型更新中添加噪声限制了不同参与者间的泄漏。实验表明,与标准联邦学习相比,应用DPOGL在保持强隐私的同时提升了模型效用。

原文摘要 · Abstract (English)

Federated Learning (FL) is the standard protocol for collaborative learning. In FL, multiple workers jointly train a shared model. They exchange model updates calculated on their data, while keeping the raw data itself local. Since workers naturally form groups based on common interests and privacy policies, we are motivated to extend standard FL to reflect a setting with multiple, potentially overlapping groups. In this setup where workers can belong and contribute to more than one group at a time, complexities arise in understanding privacy leakage and in adhering to privacy policies. To address the challenges, we propose differential private overlapping grouped learning (DPOGL), a novel method to implement privacy guarantees within overlapping groups. Under the honest-but-curious threat model, we derive novel privacy guarantees between arbitrary pairs of workers. These privacy guarantees describe and quantify two key effects of privacy leakage in DP-OGL: propagation delay, i.e., the fact that information from one group will leak to other groups only with temporal offset through the common workers and information degradation, i.e., the fact that noise addition over model updates limits information leakage between workers. Our experiments show that applying DP-OGL enhances utility while maintaining strong privacy compared to standard FL setups.

联邦学习差分隐私隐私保护分组协作

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。