提出两种隐私保护的抗恶意用户联邦学习方案,兼顾安全与数据保密。
Perfect Privacy for Discriminator-Based Byzantine-Resilient Federated Learning
- 利用小规模代表数据集和判别函数识别并过滤恶意用户贡献。
- ByITFL实现信息论级隐私,但通信开销大;LoByITFL降低开销,需可信第三方初始化。
- 理论证明隐私性、鲁棒性与收敛性,实验验证有效性,适合高安全需求场景。
联邦学习(FL)在大规模机器学习中前景广阔,但也带来新的隐私与安全挑战。本文提出ByITFL和LoByITFL两种新型FL方案,提升对恶意用户的鲁棒性,同时确保用户数据对窃听者保持隐私。为实现隐私与鲁棒性,方案依赖于联邦方拥有一个小型代表性数据集,并设计判别函数以抑制恶意用户的影响。ByITFL采用拉格朗日编码计算和重随机化,是首个具备完美信息论(IT)隐私的抗拜占庭联邦学习方案,但通信开销显著。相比之下,LoByITFL在大幅降低通信成本的同时实现相同隐私与鲁棒性,但需可信第三方参与一次性初始化阶段。本文提供了隐私性、拜占庭鲁棒性及收敛性的理论保障,并通过实验验证了方法的有效性。
原文摘要 · Abstract (English)
Federated learning (FL) shows great promise in large-scale machine learning but introduces new privacy and security challenges. We propose ByITFL and LoByITFL, two novel FL schemes that enhance resilience against Byzantine users while keeping the users' data private from eavesdroppers. To ensure privacy and Byzantine resilience, our schemes build on having a small representative dataset available to the federator and crafting a discriminator function allowing the mitigation of corrupt users' contributions. ByITFL employs Lagrange coded computing and re-randomization, making it the first Byzantine-resilient FL scheme with perfect Information-Theoretic (IT) privacy, though at the cost of a significant communication overhead. LoByITFL, on the other hand, achieves Byzantine resilience and IT privacy at a significantly reduced communication cost, but requires a Trusted Third Party, used only in a one-time initialization phase before training. We provide theoretical guarantees on privacy and Byzantine resilience, along with convergence guarantees and experimental results validating our findings.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。