FedEM通过自适应加噪,兼顾隐私保护与模型性能。
FedEM: A Privacy-Preserving Framework for Concurrent Utility Preservation in Federated Learning
- 用自适应噪声注入控制梯度泄露风险
- 在基准数据集上显著降低隐私风险并保持准确率
- 适合注重隐私与性能平衡的联邦学习场景
联邦学习(FL)允许在不共享本地数据的情况下跨分布式客户端协同训练模型,解决了去中心化系统中的隐私问题。然而,梯度共享过程可能暴露私有数据,导致真实应用中隐私保障失效。为此,我们提出联邦误差最小化(FedEM)算法,通过引入可控扰动实现自适应噪声注入,有效缓解梯度泄露攻击,同时维持模型性能。在基准数据集上的实验表明,FedEM显著降低了隐私风险,同时保持了模型准确性,实现了隐私保护与效用维持之间的稳健平衡。
原文摘要 · Abstract (English)
Federated Learning (FL) enables collaborative training of models across distributed clients without sharing local data, addressing privacy concerns in decentralized systems. However, the gradient-sharing process exposes private data to potential leakage, compromising FL's privacy guarantees in real-world applications. To address this issue, we propose Federated Error Minimization (FedEM), a novel algorithm that incorporates controlled perturbations through adaptive noise injection. This mechanism effectively mitigates gradient leakage attacks while maintaining model performance. Experimental results on benchmark datasets demonstrate that FedEM significantly reduces privacy risks and preserves model accuracy, achieving a robust balance between privacy protection and utility preservation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。