arXiv:2603.05158cs.LG2026-03

通过轮次交错策略,平衡联邦学习中的隐私、效果与效率。

Balancing Privacy-Quality-Efficiency in Federated Learning through Round-Based Interleaving of Protection Techniques

  • 设计轮次交错机制,动态组合差分隐私、同态加密与合成数据。
  • 在CIFAR-10和Fashion-MNIST上实现高隐私保护下仍保持良好学习效果。
  • 适用于对隐私和资源有不同要求的联邦学习场景。

在联邦学习中,如何平衡隐私保护、学习质量与系统效率仍是挑战。差分隐私(DP)会降低学习质量,而同态加密(HE)则带来显著系统开销。为此,我们提出Alt-FL框架,通过新颖的轮次交错策略,融合DP、HE与合成数据。提出三种新方法:隐私交错(PI)、基于DP的合成交错(SI/DP)、基于HE的合成交错(SI/HE),支持灵活的质量-效率权衡并保障隐私。在LeNet-5模型上,针对CIFAR-10与Fashion-MNIST,系统评估了包括深度梯度泄漏、反向梯度、当好奇者放弃诚实、抢夺联邦在内的典型重建攻击。引入以攻击者为中心的新评估框架,比较三种交错方法的实测攻击成功率。结果表明,在所研究的攻击模型与数据集下,PI在高隐私保护水平下表现最优,而中等隐私需求时DP方法更优。研究为不同隐私与资源约束下的隐私保护联邦学习方法选择提供依据。

原文摘要 · Abstract (English)

In federated learning (FL), balancing privacy protection, learning quality, and efficiency remains a challenge. Privacy protection mechanisms, such as Differential Privacy (DP), degrade learning quality, or, as in the case of Homomorphic Encryption (HE), incur substantial system overhead. To address this, we propose Alt-FL, a privacy-preserving FL framework that combines DP, HE, and synthetic data via a novel round-based interleaving strategy. Alt-FL introduces three new methods, Privacy Interleaving (PI), Synthetic Interleaving with DP (SI/DP), and Synthetic Interleaving with HE (SI/HE), that enable flexible quality-efficiency trade-offs while providing privacy protection. We systematically evaluate Alt-FL against representative reconstruction attacks, including Deep Leakage from Gradients, Inverting Gradients, When the Curious Abandon Honesty, and Robbing the Fed, using a LeNet-5 model on CIFAR-10 and Fashion-MNIST. To enable fair comparison between DP- and HE-based defenses, we introduce a new attacker-centric framework that compares empirical attack success rates across the three proposed interleaving methods. Our results show that, for the studied attacker model and dataset, PI achieves the most balanced trade-offs at high privacy protection levels, while DP-based methods are preferable at intermediate privacy requirements. We also discuss how such results can be the basis for selecting privacy-preserving FL methods under varying privacy and resource constraints.

联邦学习隐私保护差分隐私高效算法

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。