arXiv:2506.15181cs.LG2025-06

提升隐私保护与抗拜占庭攻击下的模型精度平衡

ImprovDML: Improved Trade-off in Private Byzantine-Resilient Distributed Machine Learning

  • 采用鲁棒向量一致性算法,确保聚合时在正常节点凸包内
  • 引入多元高斯噪声实现隐私保护,理论误差更紧致
  • 使用集中地理隐私分析,比差分隐私更好平衡精度与隐私

联合应对分布式机器学习中的拜占庭攻击与隐私泄露问题日益重要。现有方法常将抗拜占庭聚合规则与差分隐私机制结合,但导致模型精度显著下降。为此,我们提出去中心化框架ImprovDML,可在保障隐私和抗拜占庭攻击的同时保持高模型精度。该框架利用一种鲁棒向量一致性算法,在每轮迭代中计算正常节点凸包内的聚合点;同时对梯度添加多元高斯噪声以保护隐私。我们在非凸设定下提供了收敛性保证,并推导出比现有工作更紧致的渐近学习误差界。隐私分析采用集中地理隐私(concentrated geo-privacy),基于输入间的欧氏距离量化隐私,证明其在隐私与精度之间实现更优权衡。数值仿真验证了理论结果。

原文摘要 · Abstract (English)

Jointly addressing Byzantine attacks and privacy leakage in distributed machine learning (DML) has become an important issue. A common strategy involves integrating Byzantine-resilient aggregation rules with differential privacy mechanisms. However, the incorporation of these techniques often results in a significant degradation in model accuracy. To address this issue, we propose a decentralized DML framework, named ImprovDML, that achieves high model accuracy while simultaneously ensuring privacy preservation and resilience to Byzantine attacks. The framework leverages a kind of resilient vector consensus algorithms that can compute a point within the normal (non-Byzantine) agents' convex hull for resilient aggregation at each iteration. Then, multivariate Gaussian noises are introduced to the gradients for privacy preservation. We provide convergence guarantees and derive asymptotic learning error bounds under non-convex settings, which are tighter than those reported in existing works. For the privacy analysis, we adopt the notion of concentrated geo-privacy, which quantifies privacy preservation based on the Euclidean distance between inputs. We demonstrate that it enables an improved trade-off between privacy preservation and model accuracy compared to differential privacy. Finally, numerical simulations validate our theoretical results.

分布式学习隐私保护拜占庭鲁棒

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。