用近似编码计算提升联邦学习隐私保护,兼容多种模型且影响极小。
Privacy-aware Berrut Approximated Coded Computing applied to general distributed learning
- 基于贝鲁特近似编码,实现通用联邦学习的隐私保护。
- 各类模型性能损失极小,隐私泄露低于每参与方0.1比特。
- 适用于中心化与去中心化场景,计算开销仅随数据分散程度变化。
编码计算是联邦学习中用于隐私保护的技术之一。然而,现有多数编码计算方案仅在精确计算假设下有效,通常局限于特定函数类,并要求量化输入。本文提出私有贝鲁特近似编码计算(PBACC),作为增强联邦学习隐私保护的通用方法。我们推导出适用于集中式聚合、集中数据下的安全分布式训练以及去中心化数据下的安全去中心化训练的新算法,显著拓展了该方法的应用范围及可用隐私保护工具。特别地,PBACC可在多种模型上稳健提供去中心化联邦学习的隐私保障。数值实验表明,使用新编码方案对卷积神经网络、变分自编码器和Cox回归等模型的性能影响极小,且隐私泄露可严格控制在每位参与者低于0.1比特。此外,编码与解码过程的计算开销仅取决于数据的去中心化程度。
原文摘要 · Abstract (English)
Coded computing is one of the techniques that can be used for privacy protection in Federated Learning. However, most of the constructions used for coded computing work only under the assumption that the computations involved are exact, generally restricted to special classes of functions, and require quantized inputs. This paper considers the use of Private Berrut Approximate Coded Computing (PBACC) as a general solution to add strong but non-perfect privacy to federated learning. We derive new adapted PBACC algorithms for centralized aggregation, secure distributed training with centralized data, and secure decentralized training with decentralized data, thus enlarging significantly the applications of the method and the existing privacy protection tools available for these paradigms. Particularly, PBACC can be used robustly to attain privacy guarantees in decentralized federated learning for a variety of models. Our numerical results show that the achievable quality of different learning models (convolutional neural networks, variational autoencoders, and Cox regression) is minimally altered by using these new computing schemes, and that the privacy leakage can be bounded strictly to less than a fraction of one bit per participant. Additionally, the computational cost of the encoding and decoding processes depends only of the degree of decentralization of the data.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。