arXiv:2509.14603cs.LG2025-09KDD被引 2

通过概率掩码提升联邦学习隐私与异构适应性

Towards Privacy-Preserving and Heterogeneity-aware Split Federated Learning via Probabilistic Masking

  • 用概率掩码替代噪声注入,引入结构化随机性
  • 在图像和无线传感任务中准确率提升12%以上
  • 适合资源差异大、数据分布不均的现实场景

分割联邦学习(SFL)通过模型分片降低客户端计算开销,但中间激活值与模型更新的传输带来显著隐私风险,尤其易受数据重构攻击。现有基于噪声注入的防御方法常损害模型性能。为此,本文提出PM-SFL框架,采用概率掩码训练,在不依赖显式噪声的情况下引入结构化随机性,有效缓解数据重构风险并保持模型效用。针对数据异构性,设计个性化掩码学习,使子模型结构适配各客户端本地数据;针对系统异构性,提出逐层知识补偿机制,支持不同资源客户端自适应参与。理论分析证明其隐私保护能力。在图像与无线传感任务上的实验表明,PM-SFL在准确性、通信效率和抗隐私攻击方面持续优化,尤其在数据与系统异构条件下表现突出。

原文摘要 · Abstract (English)

Split Federated Learning (SFL) has emerged as an efficient alternative to traditional Federated Learning (FL) by reducing client-side computation through model partitioning. However, exchanging of intermediate activations and model updates introduces significant privacy risks, especially from data reconstruction attacks that recover original inputs from intermediate representations. Existing defenses using noise injection often degrade model performance. To overcome these challenges, we present PM-SFL, a scalable and privacy-preserving SFL framework that incorporates Probabilistic Mask training to add structured randomness without relying on explicit noise. This mitigates data reconstruction risks while maintaining model utility. To address data heterogeneity, PM-SFL employs personalized mask learning that tailors submodel structures to each client's local data. For system heterogeneity, we introduce a layer-wise knowledge compensation mechanism, enabling clients with varying resources to participate effectively under adaptive model splitting. Theoretical analysis confirms its privacy protection, and experiments on image and wireless sensing tasks demonstrate that PM-SFL consistently improves accuracy, communication efficiency, and robustness to privacy attacks, with particularly strong performance under data and system heterogeneity.

联邦学习隐私保护异构性概率掩码

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。