通过设计模型更新的偏移,保护联邦学习中的隐私。
ModShift: Model Privacy via Designed Shifts
- 用参数估计视角设计更新偏移,让窃听者难以估算模型。
- 偏移使信息矩阵奇异,显著提升窃听难度,且不降低模型精度。
- 只需低带宽安全通道,适合实际部署,可检测篡改。
本文提出一种基于偏移的模型隐私保护方法,用于防御联邦学习中的窃听攻击。将模型学习视为参数估计问题,从偏移后的更新中推导出模型更新的Fisher信息矩阵,并驱动其趋于奇异,从而制造难以求解的估计难题。偏移量由中心服务器与参与设备安全共享,确保模型准确性不受影响。文中还提出收敛性检测机制,可识别更新是否被篡改,实验表明该方案在保持模型性能的同时,相比噪声注入法实现更高程度的模型偏移,且所需保密信道带宽更低。
原文摘要 · Abstract (English)
In this paper, shifts are introduced to preserve model privacy against an eavesdropper in federated learning. Model learning is treated as a parameter estimation problem. This perspective allows us to derive the Fisher Information matrix of the model updates from the shifted updates and drive them to singularity, thus posing a hard estimation problem for Eve. The shifts are securely shared with the central server to maintain model accuracy at the server and participating devices. A convergence test is proposed to detect if model updates have been tampered with and we show that our scheme passes this test. Numerical results show that our scheme achieves a higher model shift when compared to a noise injection scheme while requiring a lesser bandwidth secret channel.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。