提出去中心化学习的差分隐私分析框架,揭示其隐私泄露与中心化方法相当。
Differential Privacy Analysis of Decentralized Gossip Averaging under Varying Threat Models
- 基于线性系统建模节点间隐私泄露,引入节点级噪声实现隐私保护。
- 隐私预算随训练轮数增长为O(T),与中心化方法同阶。
- 适用于对隐私有严格要求的去中心化机器学习场景。
在完全去中心化的机器学习中,由于缺乏中心聚合器且节点间信任假设各异,实现差分隐私(DP)保障极具挑战。本文提出一种针对基于广播平均算法的去中心化学习框架,通过添加节点级噪声并从图中任意节点视角分析隐私泄露。基于线性系统建模,我们精确刻画了节点间的隐私泄漏。核心贡献在于证明:隐私保证等价于高斯机制,其平方敏感度渐近增长为O(T),T为训练轮数,与中心化聚合情形一致。作为敏感度分析的应用,我们进一步表明:对于强凸损失函数,去中心化私有学习的过拟合风险渐近等同于中心化私有学习。
原文摘要 · Abstract (English)
Achieving differential privacy (DP) guarantees in fully decentralized machine learning is challenging due to the absence of a central aggregator and varying trust assumptions among nodes. We present a framework for DP analysis of decentralized gossip-based averaging algorithms with additive node-level noise, from arbitrary views of nodes in a graph. We present an analytical framework based on a linear systems formulation that accurately characterizes privacy leakage between nodes. Our main contribution is showing that the DP guarantees are those of a Gaussian mechanism, where the growth of the squared sensitivity is asymptotically $O(T)$, where $T$ is the number of training rounds, similarly as in the case of central aggregation. As an application of the sensitivity analysis, we show that the excess risk of decentralized private learning for strongly convex losses is asymptotically similar as in centralized private learning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。