发表机构
University of Southern California(南加州大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对联邦学习环境下的模型隐私问题,提出 MaxModShift 方案,通过设计模型偏移使窃听者无法学习模型,其性能优于 ModShift 与噪声注入方案,且所需传输功率、带宽秘密信道及平均功耗更低。
AI 中文摘要
在联邦学习环境中,将窃听者的模型学习视为一个估计问题。通过信号设计使窃听者估计问题的费舍尔信息矩阵趋于奇异,从而确保窃听者无法学习到模型。现有设计的创新之处在于,在满足各智能体传输功率约束的前提下,设计模型偏移以最大化窃听者(Eve)学习到的模型与中央服务器模型之间的差异。本文提出两种偏移方案,MaxModShift 方案的性能优于现有 ModShift 设计,且所需传输功率更低;与噪声注入方案相比,MaxModShift 性能更优,且所需的带宽秘密信道和平均功耗均更低。
英文摘要
Model learning by an eavesdropper is treated as an estimation problem in a federated environment. The Fisher Information Matrix for the eavesdropper's estimation problem is driven to singularity through a signaling design; this ensures that the eavesdropper cannot learn the model. Herein, the innovation of prior designs is that model shifts are designed to maximize the difference in the model learned by Eve and the central server while satisfying a transmission power constraint for the agents. Two shift schemes are provided. MaxModShift outperforms a prior ModShift design while requiring lesser transmission power. Compared to a noise injection scheme, MaxModShift performs better while requiring a lower bandwidth secret channel and a reduced average power consumption.
CommentsTo appear in the 2026 Asilomar Conference on Signals, Systems and Computers