arXiv:2608.09328cs.LGcs.IT2026-08

通过设计模型偏移,防止联邦学习中窃听者获取有效模型。

MaxModShift: Model Privacy via Designed Shifts

论文配图:MaxModShift: Model Privacy via Designed Shifts
图 1 · 摘自论文原文
  • 设计特定模型偏移,最大化窃听者与服务器模型差异。
  • 在相同功率下,性能优于已有偏移方案,且耗能更低。
  • 适合关注模型隐私的联邦学习系统开发者。

在联邦环境中,将窃听者(Eve)的模型学习视为估计问题。通过信号设计使窃听者的费舍尔信息矩阵趋于奇异,从而确保其无法学习到有效模型。现有方法的创新在于:设计模型偏移以最大化窃听者与中心服务器所学模型之间的差异,同时满足代理端传输功率约束。本文提出两种偏移方案,其中MaxModShift在性能上优于先前的ModShift设计,且所需传输功率更低。相较于噪声注入方案,MaxModShift在更低带宽秘密信道和更少平均功耗下表现更优。

原文摘要 · Abstract (English)

Model learning by an eavesdropper is treated as an estimation problem in a federated environment. The Fisher Information Matrix for the eavesdropper's estimation problem is driven to singularity through a signaling design; this ensures that the eavesdropper cannot learn the model. Herein, the innovation of prior designs is that model shifts are designed to maximize the difference in the model learned by Eve and the central server while satisfying a transmission power constraint for the agents. Two shift schemes are provided. MaxModShift outperforms a prior ModShift design while requiring lesser transmission power. Compared to a noise injection scheme, MaxModShift performs better while requiring a lower bandwidth secret channel and a reduced average power consumption.

联邦学习模型隐私安全通信

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。