通过双向参数扰动提升联邦学习的隐私安全与泛化能力
Secure Generalization through Stochastic Bidirectional Parameter Updates Using Dual-Gradient Mechanism
- 在模型参数空间进行细粒度扰动,生成多样化全局模型
- 在四个数据集上同时提升模型性能与抗隐私泄露能力
- 适合关注联邦学习安全与泛化性的研究人员
联邦学习(FL)因其在去中心化客户端上保护隐私协同训练而受到广泛关注,避免了敏感数据直接上传至中心服务器。然而,近期研究揭示了即使在FL框架内,仍存在暴露私有数据给攻击者的风险。现有方法通常以牺牲性能为代价来确保隐私安全。本文提出一种随机双向参数更新机制,通过在服务器端利用历史全局模型对参数空间进行系统性扰动,生成多样化的模型。通过对每个客户端在细粒度层面(如逐层调整卷积核)进行系统性扰动,生成密切邻近的多样化模型,从而提升模型的泛化能力和特征表示,同时增强对隐私攻击的鲁棒性,且不损害模型效用。我们在四个基准数据集上验证了该方法,结果表明其在模型性能和抗隐私泄露能力方面均优于现有最优方法,并通过定量与定性分析证明了有效性。
原文摘要 · Abstract (English)
Federated learning (FL) has gained increasing attention due to privacy-preserving collaborative training on decentralized clients, mitigating the need to upload sensitive data to a central server directly. Nonetheless, recent research has underscored the risk of exposing private data to adversaries, even within FL frameworks. In general, existing methods sacrifice performance while ensuring resistance to privacy leakage in FL. We overcome these issues and generate diverse models at a global server through the proposed stochastic bidirectional parameter update mechanism. Using diverse models, we improved the generalization and feature representation in the FL setup, which also helped to improve the robustness of the model against privacy leakage without hurting the model's utility. We use global models from past FL rounds to follow systematic perturbation in parameter space at the server to ensure model generalization and resistance against privacy attacks. We generate diverse models (in close neighborhoods) for each client by using systematic perturbations in model parameters at a fine-grained level (i.e., altering each convolutional filter across the layers of the model) to improve the generalization and security perspective. We evaluated our proposed approach on four benchmark datasets to validate its superiority. We surpassed the state-of-the-art methods in terms of model utility and robustness towards privacy leakage. We have proven the effectiveness of our method by evaluating performance using several quantitative and qualitative results.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。