arXiv:2504.15995cs.LGcs.AI2025-04被引 1

OPUS-VFL让垂直联邦学习更公平高效,兼顾隐私与模型贡献。

OPUS-VFL: Incentivizing Optimal Privacy-Utility Tradeoffs in Vertical Federated Learning

  • 基于贡献、隐私和资源投入的新型激励机制
  • 对抗攻击成功率降低20%,特征重建误差提升30%以上
  • 适合有异构资源的机构参与安全协作建模

垂直联邦学习(VFL)使拥有不重叠特征但共享用户群体的组织可在不共享原始数据的前提下协同训练模型。然而现有VFL系统普遍存在激励机制缺失、难以平衡隐私-效用权衡、无法适应异构资源能力等问题,导致参与度低、模型性能下降,限制实际应用。为此,本文提出OPUS-VFL——一种面向垂直联邦学习的最优隐私-效用权衡策略。该框架引入一种隐私感知的激励机制,依据模型贡献、隐私保护程度与资源投入综合奖励客户。采用轻量级留一法(LOO)量化各客户端特征重要性,并集成自适应差分隐私机制,允许客户端动态调节噪声水平以优化自身效用。系统具备可扩展性、预算平衡性,并对推理攻击和投毒攻击具有鲁棒性。在MNIST、CIFAR-10和CIFAR-100基准数据集上的大量实验表明,相比主流VFL基线,OPUS-VFL显著提升效率与鲁棒性:标签推理攻击成功率降低最高达20%,特征推理重构误差(MSE)增加超30%,对符合隐私与成本约束的高价值贡献者激励最高提升25%。结果验证了其在安全性、公平性与性能驱动方面的实用性与创新性。

原文摘要 · Abstract (English)

Vertical Federated Learning (VFL) enables organizations with disjoint feature spaces but shared user bases to collaboratively train models without sharing raw data. However, existing VFL systems face critical limitations: they often lack effective incentive mechanisms, struggle to balance privacy-utility tradeoffs, and fail to accommodate clients with heterogeneous resource capabilities. These challenges hinder meaningful participation, degrade model performance, and limit practical deployment. To address these issues, we propose OPUS-VFL, an Optimal Privacy-Utility tradeoff Strategy for VFL. OPUS-VFL introduces a novel, privacy-aware incentive mechanism that rewards clients based on a principled combination of model contribution, privacy preservation, and resource investment. It employs a lightweight leave-one-out (LOO) strategy to quantify feature importance per client, and integrates an adaptive differential privacy mechanism that enables clients to dynamically calibrate noise levels to optimize their individual utility. Our framework is designed to be scalable, budget-balanced, and robust to inference and poisoning attacks. Extensive experiments on benchmark datasets (MNIST, CIFAR-10, and CIFAR-100) demonstrate that OPUS-VFL significantly outperforms state-of-the-art VFL baselines in both efficiency and robustness. It reduces label inference attack success rates by up to 20%, increases feature inference reconstruction error (MSE) by over 30%, and achieves up to 25% higher incentives for clients that contribute meaningfully while respecting privacy and cost constraints. These results highlight the practicality and innovation of OPUS-VFL as a secure, fair, and performance-driven solution for real-world VFL.

联邦学习隐私保护激励机制差分隐私

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。