用掩码聚合保护癫痫脑电数据联邦学习,防模型更新泄露
Secure Aggregation for Privacy-Preserving Federated Learning on Clinical EEG Data

- 以掩码安全聚合为核心,结合秘密共享与容错机制
- 在模拟医疗跨机构场景中有效隐藏个体更新,保持模型训练兼容性
- 适合关注医疗数据隐私的科研与临床团队使用
联邦学习使多个机构可在不交换原始临床脑电图(EEG)数据的情况下协同训练模型,但无法完全防止从单个模型更新中泄露隐私。本文提出一种面向临床EEG数据的隐私保护联邦学习框架,核心为基于掩码的安全聚合机制。该框架融合图通信、门限秘密共享、抗丢包聚合、本地更新裁剪、可选的布隆过滤器隐私记录链接初始化模块,以及辅助公证方验证机制,支持半诚实和恶意聚合场景,基于Flower框架实现。在使用TUH EEG数据的模拟跨孤岛医疗环境中评估了不同客户端配置下的安全聚合变体。在既定假设下,安全变体能有效隐藏个体更新。结果表明,这些变体与联邦训练兼容,但恶意设置防护与轻量一致性检查机制引入额外计算、通信和轮次开销。半诚实变体开销最低,而恶意与辅助公证变体在一致性、完整性和轻量验证方面表现更强,代价更高。
原文摘要 · Abstract (English)
Federated learning enables multiple institutions to train shared models without exchanging raw clinical EEG data, but it does not fully prevent privacy leakage from individual model updates. This paper presents a privacy-preserving federated learning framework for clinical EEG data using masking-based secure aggregation as the core protection mechanism. The framework combines graph-based communication, threshold secret sharing, dropout-resilient aggregation, local update clipping, an optional Bloom filter-based privacy-preserving record-linkage initialization module, and auxiliary-notary-based verifiability. It supports both semi-honest and malicious aggregation settings and is implemented using the Flower federated learning framework. The secure-aggregation variants are evaluated in a simulated cross-silo healthcare setting using TUH EEG-derived data under different client configurations. Under the stated assumptions, the secure variants hide individual updates from the aggregation server. The results show that these variants remain compatible with federated model training, although malicious-setting safeguards and lightweight consistency-checking mechanisms introduce additional computation, communication, and round-duration overhead. The semi-honest variant provides the lowest overhead among the secure configurations, while malicious and auxiliary-notary variants offer stronger consistency, integrity, and lightweight verification support at higher cost.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。