利用无线通信噪声实现联邦学习隐私保护,无需额外加噪。
Free Privacy Protection for Wireless Federated Learning: Enjoy It or Suffer from It?
- 将传输比特翻转与通信噪声结合,构建原生信道隐私机制。
- 仅传输模型分数部分比特,避免符号和指数位错误导致灾难性后果。
- 满足(λ,ε)-Rényi差分隐私,且不影响联邦学习收敛性,适合无线环境部署。
无线联邦学习(WFL)中的固有通信噪声本可保护隐私,但传统数字通信系统采用浮点数标准(如IEEE 754)时,因比特错误可能引发灾难性后果(如符号或指数位出错),导致该潜力被忽视。本文提出一种面向WFL的信道原生比特翻转差分隐私(DP)机制,通过随机翻转发送比特并利用通信噪声,共同实现隐私保护。核心思想是将发射端的比特扰动与信道引起的比特错误视为比特翻转的DP过程。为此设计了一种新浮点转定点转换方法,仅传输模型参数的分数部分比特,规避了符号和指数位的传输,从而防止比特错误带来的严重问题。文中提出新的比特级距离度量,并证明所提机制满足(λ,ε)-Rényi DP,且不破坏WFL收敛性。实验验证了其隐私与收敛性分析的正确性,并表明该机制优于现有无信道感知的高斯差分隐私机制。
原文摘要 · Abstract (English)
Inherent communication noises have the potential to preserve privacy for wireless federated learning (WFL) but have been overlooked in digital communication systems predominantly using floating-point number standards, e.g., IEEE 754, for data storage and transmission. This is due to the potentially catastrophic consequences of bit errors in floating-point numbers, e.g., on the sign or exponent bits. This paper presents a novel channel-native bit-flipping differential privacy (DP) mechanism tailored for WFL, where transmit bits are randomly flipped and communication noises are leveraged, to collectively preserve the privacy of WFL in digital communication systems. The key idea is to interpret the bit perturbation at the transmitter and bit errors caused by communication noises as a bit-flipping DP process. This is achieved by designing a new floating-point-to-fixed-point conversion method that only transmits the bits in the fraction part of model parameters, hence eliminating the need for transmitting the sign and exponent bits and preventing the catastrophic consequence of bit errors. We analyze a new metric to measure the bit-level distance of the model parameters and prove that the proposed mechanism satisfies (λ,ε)-Rényi DP and does not violate the WFL convergence. Experiments validate privacy and convergence analysis of the proposed mechanism and demonstrate its superiority to the state-of-the-art Gaussian mechanisms that are channel-agnostic and add Gaussian noise for privacy protection.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。