arXiv:2503.09414cs.LGcs.CR2025-03

改进聚类方法,让联邦学习更私密更公平

Mitigating Membership Inference Vulnerability in Personalized Federated Learning

  • 将隐私风险评估融入聚类过程,动态选择安全的客户端分组
  • 在保持原模型准确率和公平性基础上,显著降低成员推理攻击风险
  • 特别适合数据分布不均、少数群体隐私易泄露的场景

联邦学习(FL)可在不共享用户个人数据的前提下实现协同建模,保护隐私。然而,客户端数据的非独立同分布(non-IID)特性给FL带来挑战,凸显个性化联邦学习(PFL)的重要性。在PFL中,模型需适配不同客户端的数据特征分布。一种典型方法是迭代联邦聚类算法(IFCA),通过将具有相似数据分布的客户端分组来缓解non-IID问题。尽管IFCA提升了模型准确率与公平性,但其分组策略使少数派客户(训练样本少)更容易遭受成员推理攻击(MIA)。本文提出IFCA-MIR,将MIA风险评估融入聚类过程,允许客户端根据模型性能与隐私风险双重标准选择集群。实验表明,IFCA-MIR在保持与原始IFCA相当的准确率与公平性的同时,显著降低了MIA攻击风险。

原文摘要 · Abstract (English)

Federated Learning (FL) has emerged as a promising paradigm for collaborative model training without the need to share clients' personal data, thereby preserving privacy. However, the non-IID nature of the clients' data introduces major challenges for FL, highlighting the importance of personalized federated learning (PFL) methods. In PFL, models are trained to cater to specific feature distributions present in the population data. A notable method for PFL is the Iterative Federated Clustering Algorithm (IFCA), which mitigates the concerns associated with the non-IID-ness by grouping clients with similar data distributions. While it has been shown that IFCA enhances both accuracy and fairness, its strategy of dividing the population into smaller clusters increases vulnerability to Membership Inference Attacks (MIA), particularly among minorities with limited training samples. In this paper, we introduce IFCA-MIR, an improved version of IFCA that integrates MIA risk assessment into the clustering process. Allowing clients to select clusters based on both model performance and MIA vulnerability, IFCA-MIR achieves an improved performance with respect to accuracy, fairness, and privacy. We demonstrate that IFCA-MIR significantly reduces MIA risk while maintaining comparable model accuracy and fairness as the original IFCA.

联邦学习隐私保护聚类成员推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。