arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.27108cs.CRcs.LG

SecureDrive-FL:面向联邦驾驶员监控的差分隐私与梯度感知选择性同态加密联合方案

SecureDrive-FL: Joint Differential Privacy and Gradient-Aware Selective Homomorphic Encryption for Federated Driver Monitoring

  • Institute of Industrial Automation and Software Engineering, University of Stuttgart(斯图加特大学工业自动化与软件工程研究所)
  • Eindhoven University of Technology (TU/e)(埃因霍温理工大学)

机构由 AI 辅助整理,请以论文原文为准。

Baran Can Gül, Hanuma Siddhartha Tunuguntla, Anjana Arvind Naik, Abhishek Vijay Potekar, Nasser Jazdi, Michael Weyrich

AI总结:

该研究提出SecureDrive-FL框架,结合DP-SGD与GASHE,在联邦驾驶员监控任务中实现投毒抗性与MitM拦截防护,仅增加少量运行开销。

AI中文摘要:

联邦学习(FL)支持隐私感知的分布式训练,但梯度更新仍存在被利用的风险:中间人(MitM)拦截会暴露传输中的更新,而模型投毒会破坏全局收敛。我们首先提出GASHE(Gradient-Aware Selective Homomorphic Encryption,梯度感知选择性同态加密),这是一种新型选择性加密策略,动态识别并仅加密超出差分隐私(DP)校准敏感度阈值的梯度分量,而非像静态基于层的方案或全参数CKKS方案那样统一加密所有参数。基于GASHE,我们提出SecureDrive-FL,这是一种联邦驾驶员监控框架,将DP-SGD与GASHE结合,构建了首个闭环DP+HE隐私流水线:DP-SGD校准参数直接推导GASHE加密掩码,统一训练时隐私与通信时机密性。在非IID联邦划分下的10类分心驾驶员分类任务上评估,SecureDrive-FL在投毒抗性上与单独DP-SGD相当(准确率73.6% vs. 74.0%,攻击成功率均为3.9%),同时还能抵御MitM拦截,而单独DP-SGD在该场景下准确率降至接近随机水平(78.2% vs. 10.4%),所有结果均在仅比单独DP-SGD多约8%-10%的运行时开销下获得——在每轮隐私参数ε₀=4的DP-SGD噪声注入条件下。

英文摘要:

Federated Learning (FL) enables privacy-aware distributed training, yet gradient updates remain exploitable: Man-in-the-Middle (MitM) interception exposes updates in transit, while model poisoning corrupts global convergence. We first introduce GASHE (Gradient-Aware Selective Homomorphic Encryption), a novel selective encryption strategy that dynamically identifies and encrypts only the gradient components exceeding a DP-calibrated sensitivity threshold, rather than encrypting all parameters uniformly as in static layer-based or full-parameter CKKS schemes. Building on GASHE, we introduce SecureDrive-FL, a federated driver monitoring framework that couples DP-SGD with GASHE to create the first closed-loop DP+HE privacy pipeline: DP-SGD calibration parameters directly derive the GASHE encryption mask, unifying training-time privacy and communication-time confidentiality. Evaluated on a ten-class distracted driver classification task under non-IID federated splits, SecureDrive-FL matches DP-SGD alone's poisoning resistance (73.6% vs. 74.0% accuracy, 3.9% Attack Success Rate for both) while additionally withstanding MitM interception, where DP-SGD alone collapses to near-random accuracy (78.2% vs. 10.4%), all under only approx. 8--10% additional runtime overhead relative to DP-SGD alone---under DP-SGD noise injection with per-round privacy parameter epsilon_0=4.

↑