无需信任服务器,也能实现隐私保护与抗攻击的联邦学习。
Towards Trustworthy Federated Learning with Untrusted Participants
- 利用参与者间共享随机种子,注入相关噪声提升鲁棒性。
- 隐私保护效果显著优于本地差分隐私,接近可信服务器水平。
- 适合对隐私和系统安全性要求高的分布式学习场景。
抵御恶意参与者和保障数据隐私是可信联邦学习的关键,但通常需假设中心服务器可信。本文证明:仅需参与者间共享未知于他人的随机种子这一更弱假设即可。在恶意参与者可与不可信服务器合谋的场景下,提出CafCor算法,融合鲁棒梯度聚合与相关噪声注入,利用参与者间的共享随机性。理论证明CafCor实现强隐私-效用权衡,显著优于不作信任假设的本地差分隐私(DP)方法,且逼近全可信服务器下的中央差分隐私(central DP)性能。标准基准上的实证结果验证了其可行性,表明在不依赖服务器信任的前提下,隐私与鲁棒性可兼得而不损失效用。
原文摘要 · Abstract (English)
Resilience against malicious participants and data privacy are essential for trustworthy federated learning, yet achieving both with good utility typically requires the strong assumption of a trusted central server. This paper shows that a significantly weaker assumption suffices: each pair of participants shares a randomness seed unknown to others. In a setting where malicious participants may collude with an untrusted server, we propose CafCor, an algorithm that integrates robust gradient aggregation with correlated noise injection, using shared randomness between participants. We prove that CafCor achieves strong privacy-utility trade-offs, significantly outperforming local differential privacy (DP) methods, which do not make any trust assumption, while approaching central DP utility, where the server is fully trusted. Empirical results on standard benchmarks validate CafCor's practicality, showing that privacy and robustness can coexist in distributed systems without sacrificing utility or trusting the server.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。