arXiv:2510.23463cs.LGcs.CR2025-10被引 3

无线联邦学习中,信道噪声可自然带来隐私保护,无需额外加噪。

Differential Privacy as a Perk: Federated Learning over Multiple-Access Fading Channels with a Multi-Antenna Base Station

  • 利用多天线基站与信道噪声实现无需人工加噪的差分隐私
  • 在非凸损失函数下证明了训练收敛性与隐私边界的联合优化
  • 理论揭示无损隐私保护的条件,适合无线联邦学习研究者

联邦学习通过避免原始数据传输来保护隐私,在基于无线传输的空中计算(AirFL)场景中,信道噪声既是干扰源也是隐私保护的天然随机性来源。现有工作受限于简单信道或特定损失函数,通常仅考虑单轮或非收敛的隐私界。本文研究多址衰落信道下多天线基站的空口联邦学习,满足用户级差分隐私(DP)要求。尽管有研究声称必须注入人工噪声才能保证隐私,我们却发现:在一般有界参数假设下,无需任何人工噪声即可实现收敛的差分隐私。我们推导出新的隐私边界,并在广义光滑非凸损失函数下建立收敛性保证。进一步优化接收波束成形与功率分配,刻画了收敛性与隐私之间的最优权衡,明确揭示了不牺牲训练性能即可实现隐私保护的条件。大量数值实验验证了理论结果。

原文摘要 · Abstract (English)

Federated Learning (FL) is a distributed learning paradigm that preserves privacy by eliminating the need to exchange raw data during training. In its prototypical edge instantiation with underlying wireless transmissions enabled by analog over-the-air computing (AirComp), referred to as \emph{over-the-air FL (AirFL)}, the inherent channel noise plays a unique role of \emph{frenemy} in the sense that it degrades training due to noisy global aggregation while providing a natural source of randomness for privacy-preserving mechanisms, formally quantified by \emph{differential privacy (DP)}. It remains, nevertheless, challenging to effectively harness such channel impairments, as prior arts, under assumptions of either simple channel models or restricted types of loss functions, mostly considering (local) DP enhancement with a single-round or non-convergent bound on privacy loss. In this paper, we study AirFL over multiple-access fading channels with a multi-antenna base station (BS) subject to user-level DP requirements. Despite a recent study, which claimed in similar settings that artificial noise (AN) must be injected to ensure DP in general, we demonstrate, on the contrary, that DP can be gained as a \emph{perk} even \emph{without} employing any AN. Specifically, we derive a novel bound on DP that converges under general bounded-domain assumptions on model parameters, along with a convergence bound with general smooth and non-convex loss functions. Next, we optimize over receive beamforming and power allocations to characterize the optimal convergence-privacy trade-offs, which also reveal explicit conditions in which DP is achievable without compromising training. Finally, our theoretical findings are validated by extensive numerical results.

联邦学习差分隐私无线通信空口计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。