QuanCrypt-FL:面向安全联邦学习的量化同态加密与剪枝方法
QuanCrypt-FL: Quantized Homomorphic Encryption with Pruning for Secure Federated Learning
- The Knight Foundation School of Computing and Information Sciences, Florida International University(佛罗里达国际大学骑士基金会计算与信息科学学院)
- Sustainability, Optimization, and Learning for InterDependent networks laboratory(相互依赖网络的可持续性、优化与学习实验室)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
针对联邦学习易受推理攻击且同态加密开销大的问题,提出结合低位量化、剪枝和均值裁剪的QuanCrypt-FL算法,在MNIST、CIFAR-10/100上实现高精度、低开销,加密/解密/推理分别提速9倍/16倍/1.5倍。
AI中文摘要:
联邦学习已成为去中心化机器学习的一种领先方法,使多个客户端能够在无需交换私有数据的情况下协作训练共享模型。尽管联邦学习增强了数据隐私,但在训练和推理阶段,它仍然容易受到推理攻击,如梯度反演和成员推理攻击。同态加密通过加密模型更新来防范此类攻击,提供了一种有前景的解决方案,但会引入大量通信开销,从而减慢训练速度并增加计算成本。为了解决这些挑战,我们提出了QuanCrypt-FL,一种新颖的算法,它结合了低位量化和剪枝技术,以增强对攻击的防护,同时显著降低训练期间的计算成本。此外,我们提出并实现了基于均值的裁剪,以缓解量化溢出或误差。通过整合这些方法,QuanCrypt-FL构建了一个通信高效的联邦学习框架,在确保隐私保护的同时,对模型精度的影响最小,从而提高了计算效率和攻击韧性。我们在MNIST、CIFAR-10和CIFAR-100数据集上验证了我们的方法,展示了相较于最先进方法的优越性能。QuanCrypt-FL在不同客户端数量下始终优于现有方法,并在精度上与Vanilla-FL相匹配。此外,与BatchCrypt相比,QuanCrypt-FL实现了高达9倍的加密加速、16倍的解密加速和1.5倍的推理加速,训练时间最多减少3倍。
英文摘要:
Federated Learning has emerged as a leading approach for decentralized machine learning, enabling multiple clients to collaboratively train a shared model without exchanging private data. While FL enhances data privacy, it remains vulnerable to inference attacks, such as gradient inversion and membership inference, during both training and inference phases. Homomorphic Encryption provides a promising solution by encrypting model updates to protect against such attacks, but it introduces substantial communication overhead, slowing down training and increasing computational costs. To address these challenges, we propose QuanCrypt-FL, a novel algorithm that combines low-bit quantization and pruning techniques to enhance protection against attacks while significantly reducing computational costs during training. Further, we propose and implement mean-based clipping to mitigate quantization overflow or errors. By integrating these methods, QuanCrypt-FL creates a communication-efficient FL framework that ensures privacy protection with minimal impact on model accuracy, thereby improving both computational efficiency and attack resilience. We validate our approach on MNIST, CIFAR-10, and CIFAR-100 datasets, demonstrating superior performance compared to state-of-the-art methods. QuanCrypt-FL consistently outperforms existing method and matches Vanilla-FL in terms of accuracy across varying client. Further, QuanCrypt-FL achieves up to 9x faster encryption, 16x faster decryption, and 1.5x faster inference compared to BatchCrypt, with training time reduced by up to 3x.