arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

用于临床脑电数据隐私保护联邦学习的安全聚合

Secure Aggregation for Privacy-Preserving Federated Learning on Clinical EEG Data

Pouya Rajabi, Mohsen Toorani

arXiv 2607.28191首次发表:更新:

发表机构

University of South-Eastern Norway(东南挪威大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对临床EEG数据联邦学习的隐私泄露问题,提出以掩码安全聚合为核心的隐私保护框架,经模拟医疗场景验证,半诚实变体开销低,恶意变体安全性强但开销更高。

AI 中文摘要

联邦学习允许多个机构在不交换原始临床脑电(EEG)数据的情况下训练共享模型,但无法完全防止来自单个模型更新的隐私泄露。本文提出一种用于临床EEG数据的隐私保护联邦学习框架,以基于掩码的安全聚合作为核心保护机制。该框架结合了基于图的通信、门限秘密共享、抗失活聚合、局部更新裁剪、可选的基于布隆过滤器的隐私保护记录链接初始化模块,以及基于辅助公证人的可验证性。它支持半诚实和恶意聚合设置,并使用Flower联邦学习框架实现。在模拟的跨机构医疗场景中,使用TUH EEG衍生数据在不同客户端配置下对安全聚合变体进行评估。在所述假设下,安全变体可向聚合服务器隐藏单个更新。结果表明,这些变体仍与联邦模型训练兼容,尽管恶意设置的安全措施和轻量级一致性检查机制会引入额外的计算、通信和轮次时长开销。半诚实变体在安全配置中开销最低,而恶意和辅助公证变体以更高成本提供更强的一致性、完整性和轻量级验证支持。

英文摘要

Federated learning enables multiple institutions to collaboratively train a shared model without exchanging their raw data. However, individual model updates are data-dependent and may reveal information about clients' local training data. This paper presents a privacy-preserving federated learning framework for clinical EEG data that uses masking-based secure aggregation as its core protection mechanism. The framework combines graph-based communication, threshold secret sharing, dropout recovery, local update clipping, an optional Bloom filter-based privacy-preserving record-linkage initialization module, and auxiliary-notary-based verifiability. It supports semi-honest and malicious aggregation settings and is implemented using the Flower federated learning framework. The secure aggregation variants are evaluated in a simulated cross-silo healthcare setting using TUH EEG-derived data under different client configurations. Under the stated assumptions, the secure variants hide individual updates from the aggregation server. The results show that these variants remain compatible with federated model training, although malicious-setting safeguards and lightweight consistency-checking mechanisms introduce additional computation, communication, and round-duration overhead. Among the proposed secure configurations, the base semi-honest variant incurs the lowest overhead; the malicious-server variants add protocol-consistency and authenticity safeguards, and the auxiliary-notary variants add lightweight aggregate-consistency checking.

Comments28 pages, 6 figures, 7 tables. A version of this manuscript will appear in the Proceedings of the International Workshop on Hot Topics at the Intersection of Distributed Machine Learning and Security (HotDiSec 2026), co-located with ESORICS 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑