通过梯度与训练图像的双重混淆增强联邦学习中的隐私性
Enhancing Privacy in Federated Learning via Dual Obfuscation of Gradients and Training Images
浏览论文内容
中文总结 AI 辅助
该研究针对联邦学习中模型更新易泄露训练数据的问题,提出结合随机二值权重梯度修改与客户端-图像独立密钥图像加密的双重混淆方法,可减少视觉信息泄露且不显著降低分类性能。
中文摘要 AI 辅助
联邦学习可实现协同模型训练,同时将数据保留在各客户端本地;但近期研究表明,可从共享的模型更新中重构训练数据。为解决该问题,本文提出一种双重混淆方法,通过联合混淆更新信息与训练图像,增强对图像重构攻击的鲁棒性。该方法结合了基于随机二值权重的鲁棒性增强技术与图像加密技术:前者随机将部分梯度元素置零,减少攻击者可获取的原始梯度信息量;后者为各客户端及各图像提供独立密钥,避免显式密钥共享,降低重构图像的视觉可解释性,二者形成互补保护。在使用Vision Transformer(ViT)的图像分类任务实验中,所提方法在评估设置下减少了Attention Privacy Leakage(APRIL)可恢复的视觉信息,且未造成超出图像加密本身的分类性能下降。尽管该组合无法提供绝对安全保证,但结果表明,梯度修改与图像加密结合在隐私增强联邦学习中具有潜在益处。
英文摘要
Federated learning enables collaborative model training while keeping data locally at each client; however, recent studies have shown that training data can be reconstructed from shared model updates. To address this issue, this paper proposes a dual obfuscation method that enhances robustness against image restoration attacks by jointly obfuscating updated information and training images. The proposed method combines a robustness enhancement technique based on random binary weights, which randomly sets a portion of gradient elements to zero, with an image encryption technique. These techniques provide complementary protection by reducing the amount of original gradient information available to an attacker and the visual interpretability of reconstructed images, respectively. Furthermore, the image encryption technique allows independent keys to be used for each client and each image, avoiding explicit key sharing. Experimental results on an image classification task using a Vision Transformer (ViT) show that the proposed method reduces the visual information recovered by Attention Privacy Leakage (APRIL) under the evaluated settings without causing additional degradation in classification performance beyond that caused by image encryption. Although the proposed combination does not provide an absolute security guarantee, the results demonstrate the potential benefit of combining gradient modification and image encryption for privacy-enhanced federated learning.