一种用于加速隐私保护联邦学习的选性同态加密方法
A Selective Homomorphic Encryption Approach for Faster Privacy-Preserving Federated Learning
- A. Korkmaz Dept. of Electrical Engineering \& Computer Science, The University of Missouri, Columbia, USA P. Rao Dept. of Electrical Engineering \& Computer Science, The University of Missouri, Columbia, USA
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
FAS通过结合选择性同态加密、差分隐私和位操作,实现高效安全的联邦学习,比传统FHE快90%并提升实用性。
AI中文摘要:
联邦学习(FL)在医疗健康领域隐私保护机器学习中已成为关键方法,允许在去中心化的医疗数据集上进行协作模型训练而无需交换客户端的数据。然而,这些系统的当前安全实现面临一个根本性的权衡:严格加密保护如完全同态加密(FHE)会带来沉重的计算开销,而轻量级替代方案则可能通过模型更新导致数据泄露。为了解决这个问题,我们提出了FAS(快速且安全的联邦学习),一种新的方法,通过战略性地结合选择性同态加密、差分隐私和位操作来实现稳健的安全性,而不会影响实际可用性。我们的方法消除了模型预训练阶段的需要,通过分层加密和混淆动态保护高风险模型参数。我们使用Flower框架实现了FAS,并在十一台物理机器的集群上进行了评估。我们的方法比在模型权重上应用FHE快多达90%。此外,我们消除了竞争对手如FedML-HE和MaskCrypt所需计算开销。我们的方法比竞争对手快1.5倍,同时达到可比的安全性结果。在医疗影像数据集上的实验评估证实,FAS在对抗梯度反转攻击时与传统FHE保持相似的安全结果,同时保持诊断模型的准确性。这些结果使FAS成为对延迟敏感的医疗应用中隐私保护和计算效率都要求的实用解决方案。
英文摘要:
Federated learning (FL) has come forward as a critical approach for privacy-preserving machine learning in healthcare, allowing collaborative model training across decentralized medical datasets without exchanging clients' data. However, current security implementations for these systems face a fundamental trade-off: rigorous cryptographic protections like fully homomorphic encryption (FHE) impose prohibitive computational overhead, while lightweight alternatives risk vulnerable data leakage through model updates. To address this issue, we present FAS (Fast and Secure Federated Learning), a novel approach that strategically combines selective homomorphic encryption, differential privacy, and bitwise scrambling to achieve robust security without compromising practical usability. Our approach eliminates the need for model pretraining phases while dynamically protecting high-risk model parameters through layered encryption and obfuscation. We implemented FAS using the Flower framework and evaluated it on a cluster of eleven physical machines. Our approach was up to 90\% faster than applying FHE on the model weights. In addition, we eliminated the computational overhead that is required by competitors such as FedML-HE and MaskCrypt. Our approach was up to 1.5$\times$ faster than the competitors while achieving comparable security results. Experimental evaluations on medical imaging datasets confirm that FAS maintains similar security results to conventional FHE against gradient inversion attacks while preserving diagnostic model accuracy. These results position FAS as a practical solution for latency-sensitive healthcare applications where both privacy preservation and computational efficiency are requirements.