基于个性化本地动量的自适应差分隐私联邦学习OA
Personalized federated learning via adaptive differential privacy with local momentum
联邦学习(Federated Learning,FL)是一种分布式机器学习技术,允许多个设备或组织通过共享训练参数而非原始数据进行模型训练.然而,攻击者仍可能对这些训练参数实施推理攻击(如差分攻击)来推断个体信息.因此,差分隐私(Differential Privacy,DP)技术被广泛应用于联邦学习中以防御此类攻击.文中基于客户级(Client-Level)差分隐私噪声优化的联邦学习场景,设计了一种基于个性化本地动量的自适应差分隐私联邦学习算法.具体而言,通过在客户端本地设置个性化动量对本地模型进行动态校准,以克服客户端漂移问题;其次,设计通过裁剪阈值自适应衰落实现的自适应DP方法,可动态优化各客户端的噪声添加规模.在Cifar10、Cifar100和SVHN数据集上的实验结果表明,相同隐私保护级别下,该算法性能优于已有工作.
Federated learning(FL)is a distributed machine learning paradigm that enables multiple de-vices or organizations to collaboratively train models by sharing training parameters instead of raw data.However,shared parameters remain vulnerable to inference attacks,e.g.differential attacks,which can still compromise individual privacy.To mitigate such threats,differential privacy(DP)has been widely adopted in FL frameworks.This paper investigates a client-level DP federated learning scenario with noise optimization,and proposes an adaptive DP-FL algorithm based on personalized local momentum.Specifically,we first implement dynamic calibration of local models through client-specific momentum mechanisms to address the client drift problem.Furthermore,we design an adaptive DP mechanism fea-turing decaying clipping thresholds,which dynamically optimizes the noise injection scale for individual clients.Experimental evaluations on Cifar10,Cifar100,and SVHN datasets demonstrate that our algo-rithm outperforms existing approaches under equivalent privacy protection levels.
杨健;张世召;夏友旭;王藤遇;钱奕安
南京邮电大学 计算机学院,江苏 南京 210023南京邮电大学 计算机学院,江苏 南京 210023南京邮电大学 计算机学院,江苏 南京 210023南京邮电大学 计算机学院,江苏 南京 210023南京邮电大学 计算机学院,江苏 南京 210023
信息技术与安全科学
联邦学习差分隐私数据异构动量自适应噪声
federated learning(FL)differential privacy(DP)data heterogeneitymomentumadap-tive noise
《南京邮电大学学报(自然科学版)》 2026 (2)
56-65,10
国家自然科学基金青年基金(62201285)和江苏省研究生科研与实践创新计划(SJCX24_0317)资助项目
评论