提出可验证的联邦学习聚合协议,解决梯度泄露与中毒攻击问题。
Privacy-Preserving Federated Learning from Partial Decryption Verifiable Threshold Multi-Client Functional Encryption
- 基于部分可验证的阈值多客户端功能加密构造新方案
- 在MNIST上实现相同精度下训练时间减少40%以上,通信量降50%
- 适合资源受限的物联网设备部署
在联邦学习中,多方可在不直接交换私有数据的情况下协同训练模型,但梯度泄露问题仍威胁隐私安全与模型完整性。现有方案虽使用阈值密码学缓解推断攻击,却无法保证聚合结果的可验证性,易受投毒攻击影响。本文构建一种部分可验证的阈值多客户端功能加密方案,并应用于联邦学习,实现可验证阈值安全聚合协议(VTSAFL)。该协议使客户端能够验证聚合结果,同时最小化计算与通信开销。方案的功能密钥和部分解密结果大小恒定,保障大规模部署效率。在MNIST数据集上的实验表明,VTSAFL在达到与现有方案相同准确率的同时,总训练时间减少40%以上,通信开销降低最多50%。这一效率对克服物联网设备固有的资源限制至关重要。
原文摘要 · Abstract (English)
In federated learning, multiple parties can cooperate to train the model without directly exchanging their own private data, but the gradient leakage problem still threatens the privacy security and model integrity. Although the existing scheme uses threshold cryptography to mitigate the inference attack, it can not guarantee the verifiability of the aggregation results, making the system vulnerable to the threat of poisoning attack. We construct a partial decryption verifiable threshold multi client function encryption scheme, and apply it to Federated learning to implement the federated learning verifiable threshold security aggregation protocol (VTSAFL). VTSAFL empowers clients to verify aggregation results, concurrently minimizing both computational and communication overhead. The size of the functional key and partial decryption results of the scheme are constant, which provides efficiency guarantee for large-scale deployment. The experimental results on MNIST dataset show that vtsafl can achieve the same accuracy as the existing scheme, while reducing the total training time by more than 40%, and reducing the communication overhead by up to 50%. This efficiency is critical for overcoming the resource constraints inherent in Internet of Things (IoT) devices.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。