通过动态稀疏更新提升隐私保护下的个性化联邦学习效果
Differential Privacy Personalized Federated Learning Based on Dynamically Sparsified Client Updates
- 用重参数化选择个性化更新,减少传输数据量
- 动态自适应范数控制更新范围,降低噪声影响
- 在多个数据集上表现更优,适合复杂场景
个性化联邦学习广泛应用于数据异构场景,可在数据持有终端实现更高效、自动化的本地训练,包括自动选择高性能模型参数上传,从而提升整体训练效率。然而,该方法存在显著的隐私泄露风险。现有研究尝试通过差分隐私缓解此问题,但仍存在两大局限:(1)差分隐私与个性化融合不足,导致模型引入过多噪声;(2)未能有效控制模型更新信息的空间范围,造成隐私与模型性能之间平衡不佳。本文提出一种基于动态稀疏客户端更新的差分隐私个性化联邦学习方法(DP-pFedDSU),通过重参数化训练实现个性化更新信息的有效筛选,减少更新数量;同时采用动态自适应范数,在训练过程中控制模型更新的范数空间,减轻截断对更新信息的负面影响。这些策略显著提升了差分隐私与个性化联邦学习的融合效果。在EMNIST、CIFAR-10和CIFAR-100上的实验结果表明,所提方案性能优越,适用于更复杂的个性化联邦学习场景。
原文摘要 · Abstract (English)
Personalized federated learning is extensively utilized in scenarios characterized by data heterogeneity, facilitating more efficient and automated local training on data-owning terminals. This includes the automated selection of high-performance model parameters for upload, thereby enhancing the overall training process. However, it entails significant risks of privacy leakage. Existing studies have attempted to mitigate these risks by utilizing differential privacy. Nevertheless, these studies present two major limitations: (1) The integration of differential privacy into personalized federated learning lacks sufficient personalization, leading to the introduction of excessive noise into the model. (2) It fails to adequately control the spatial scope of model update information, resulting in a suboptimal balance between data privacy and model effectiveness in differential privacy federated learning. In this paper, we propose a differentially private personalized federated learning approach that employs dynamically sparsified client updates through reparameterization and adaptive norm(DP-pFedDSU). Reparameterization training effectively selects personalized client update information, thereby reducing the quantity of updates. This approach minimizes the introduction of noise to the greatest extent possible. Additionally, dynamic adaptive norm refers to controlling the norm space of model updates during the training process, mitigating the negative impact of clipping on the update information. These strategies substantially enhance the effective integration of differential privacy and personalized federated learning. Experimental results on EMNIST, CIFAR-10, and CIFAR-100 demonstrate that our proposed scheme achieves superior performance and is well-suited for more complex personalized federated learning scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。