arXiv:2510.19934cs.LGcs.CR2025-10被引 8

用f-差分隐私改进去中心化联邦学习的隐私-效用平衡

Mitigating Privacy-Utility Trade-off in Decentralized Federated Learning via $f$-Differential Privacy

  • 基于f-差分隐私设计新会计方法,适配去中心化通信与本地更新
  • 在真实和合成数据上实现更紧的隐私边界与更好模型性能
  • 适合关注隐私保护联邦学习的科研人员与系统开发者

差分隐私的去中心化联邦学习允许用户在不共享数据的情况下协作。然而,由于存在复杂的算法组件(如去中心化通信和本地更新),准确量化隐私预算极具挑战。本文在f-差分隐私框架下,针对两种去中心化FL算法提出新的隐私会计方法:成对网络f-DP(PN-f-DP),用于量化随机游走通信下用户对间的隐私泄露;基于密钥的f-局部差分隐私(Sec-f-LDP),支持通过共享密钥注入结构化噪声。结合f-DP理论与马尔可夫链浓度工具,该框架捕捉了稀疏通信、本地迭代和相关噪声带来的隐私放大效应。在合成与真实数据集上的实验表明,相比Rényi DP方法,本方法获得更紧的(ε,δ)界并提升模型效用,凸显f-DP在去中心化隐私会计中的优势。

原文摘要 · Abstract (English)

Differentially private (DP) decentralized Federated Learning (FL) allows local users to collaborate without sharing their data with a central server. However, accurately quantifying the privacy budget of private FL algorithms is challenging due to the co-existence of complex algorithmic components such as decentralized communication and local updates. This paper addresses privacy accounting for two decentralized FL algorithms within the $f$-differential privacy ($f$-DP) framework. We develop two new $f$-DP-based accounting methods tailored to decentralized settings: Pairwise Network $f$-DP (PN-$f$-DP), which quantifies privacy leakage between user pairs under random-walk communication, and Secret-based $f$-Local DP (Sec-$f$-LDP), which supports structured noise injection via shared secrets. By combining tools from $f$-DP theory and Markov chain concentration, our accounting framework captures privacy amplification arising from sparse communication, local iterations, and correlated noise. Experiments on synthetic and real datasets demonstrate that our methods yield consistently tighter $(ε,δ)$ bounds and improved utility compared to Rényi DP-based approaches, illustrating the benefits of $f$-DP in decentralized privacy accounting.

联邦学习差分隐私去中心化隐私会计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。