解决异构数据下联邦学习的隐私与抗拜占庭攻击难题
Private Aggregation for Byzantine-Resilient Heterogeneous Federated Learning
- 通过可验证秘密共享与私有信息检索的协同设计,实现信息论级隐私保护
- 在异构数据场景下仍保持梯度聚合鲁棒性,对抗多种恶意攻击
- 兼容零阶估计技术,降低通信开销,适合大规模实际部署
在联邦学习中,如何在保障客户端数据隐私的同时抵御拜占庭客户端的干扰,是核心挑战。当客户端数据同质时,可通过安全聚合等信息论方法实现鲁棒聚合;但该方法在数据异构时失效。虽有最近邻混合等预处理技术提升异构场景性能,却无法与现有隐私机制兼容。本文提出多阶段联合设计方法,结合可验证秘密共享、安全聚合与定制对称私有信息检索,实现异构数据下的信息论级隐私与拜占庭容错。实验表明,该方案在多种攻击下优于已有技术。针对安全聚合带来的通信开销问题,进一步研究其与零阶估计方法的协同,有效降低通信成本,提升私有聚合在主流联邦学习任务中的可扩展性。
原文摘要 · Abstract (English)
Ensuring resilience to Byzantine clients while maintaining the privacy of the clients' data is a fundamental challenge in federated learning (FL). When the clients' data is homogeneous, suitable countermeasures were studied from an information-theoretic perspective utilizing secure aggregation techniques while ensuring robust aggregation of the clients' gradients. However, the countermeasures used fail when the clients' data is heterogeneous. Suitable pre-processing techniques, such as nearest neighbor mixing, were recently shown to enhance the performance of those countermeasures in the heterogeneous setting. Nevertheless, those pre-processing techniques cannot be applied with the introduced privacy-preserving mechanisms. We propose a multi-stage method encompassing a careful co-design of verifiable secret sharing, secure aggregation, and a tailored symmetric private information retrieval scheme to achieve information-theoretic privacy guarantees and Byzantine resilience under data heterogeneity. We evaluate the effectiveness of our scheme on a variety of attacks and show how it outperforms the previously known techniques. Since the communication overhead of secure aggregation is non-negligible, we investigate the interplay with zero-order estimation methods that reduce the communication cost in state-of-the-art FL tasks and thereby make private aggregation scalable.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。