arXiv:2509.13739cs.LGcs.DC2025-09被引 1

提出并行保护框架,灵活平衡联邦学习的隐私、效率与模型性能。

ParaAegis: Parallel Protection for Flexible Privacy-preserved Federated Learning

  • 通过分层策略,对模型不同部分分别使用轻量DP和全同态加密。
  • 实验显示可自由调节训练时间与模型精度,保持相同隐私水平。
  • 适合需要灵活控制隐私与效率权衡的工业级联邦学习场景。

联邦学习面临严峻困境:现有保护机制如差分隐私(DP)和全同态加密(HE)强制在模型效用与计算效率之间做出取舍,缺乏灵活性,阻碍实际应用。为此,我们提出ParaAegis,一种并行保护框架,使实践者能够灵活调控隐私-效用-效率的平衡。核心创新在于策略性模型分割:对模型中低范数、不关键的部分应用轻量级差分隐私,其余部分则采用全同态加密保护,并通过分布式投票机制达成分割共识。理论分析表明,在相同隐私条件下,系统可在效率与效用间自由调整。关键实验结果证明,通过调节超参数,可实现对模型精度与训练时间的灵活优先级配置。

原文摘要 · Abstract (English)

Federated learning (FL) faces a critical dilemma: existing protection mechanisms like differential privacy (DP) and homomorphic encryption (HE) enforce a rigid trade-off, forcing a choice between model utility and computational efficiency. This lack of flexibility hinders the practical implementation. To address this, we introduce ParaAegis, a parallel protection framework designed to give practitioners flexible control over the privacy-utility-efficiency balance. Our core innovation is a strategic model partitioning scheme. By applying lightweight DP to the less critical, low norm portion of the model while protecting the remainder with HE, we create a tunable system. A distributed voting mechanism ensures consensus on this partitioning. Theoretical analysis confirms the adjustments between efficiency and utility with the same privacy. Crucially, the experimental results demonstrate that by adjusting the hyperparameters, our method enables flexible prioritization between model accuracy and training time.

联邦学习隐私保护并行计算可调平衡

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。