arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.23521cs.LGcs.NI

住宅流量分类中的特征抑制与差分隐私:一项双家庭联邦研究

Feature Suppression and Differential Privacy for Residential Traffic Classification: A Two-Home Federated Study

  • Budapest University of Technology and Economics(布达佩斯科技经济大学)
  • CUJO LLC Hungary(CUJO有限责任公司匈牙利分公司)

机构由 AI 辅助整理,请以论文原文为准。

Márton Pál Lipcsey-Magyar, Adrian Pekar

AI总结:

本研究通过双家庭联邦学习模拟,比较特征抑制与差分隐私在住宅流量分类中的效果,发现特征抑制在宏F1和最差组F1上优于DP-SGD,但缺乏正式隐私保证,可作为输入最小化基线。

AI中文摘要:

住宅流量分类支持服务管理,但跨家庭的联邦学习必须考虑异构流量和隐私约束。隐私感知训练可能在不同流量类别上施加不均衡的成本。我们在模拟的双客户端联邦学习中研究了这一权衡,使用了162万条预处理后的网关采集流量,涵盖六个类别。我们在一个固定的记录级隐私设置下,比较了全特征基线、特征抑制(FS)和差分隐私随机梯度下降(DP-SGD)。FS-mild从16个模型输入中排除了四个时序特征;它不提供正式的隐私保证。在按规模比例聚合下,FS-mild在分层和时间划分下,在两种模型容量下,所有五个随机种子中,其组合宏F1和最差组F1(各家庭中每类F1的最小值)均高于DP-SGD。所测试的DP-SGD配置在少数类别上产生了显著的损失,尤其是在较小的家庭中,但FS-mild并未在统一改进上优于全特征基线。在分层划分的模型上,基于损失和影子模型的成员推理探针显示,聚合判别接近随机水平,且各探针之间没有一致的排名;这并不能确立等效的隐私。这些发现支持FS作为输入最小化的基线,而非正式隐私的替代品。

英文摘要:

Residential traffic classification supports service management, but learning across homes must account for heterogeneous traffic and privacy constraints. Privacy-aware training may impose uneven costs across traffic categories. We study this tradeoff in simulated two-client federated learning using 1.62 million preprocessed gateway-collected flows across six categories. We compare a full-feature baseline, feature suppression (FS), and differentially private stochastic gradient descent (DP-SGD) under one fixed record-level privacy setting. FS-mild excludes four timing features from 16 model inputs; it provides no formal privacy guarantee. With size-proportional aggregation, FS-mild achieves higher combined macro-F1 and worst-group F1 (the minimum per-class F1 across homes) than DP-SGD in all five seeds at both model capacities under stratified and temporal splits. The tested DP-SGD configuration incurs pronounced minority-category losses, especially in the smaller home, but FS-mild does not uniformly improve on the full-feature baseline. On stratified-split models, loss-based and shadow-model membership probes show near-chance aggregate discrimination without a consistent ranking across probes; this does not establish equivalent privacy. These findings support FS as an input-minimization baseline, not a substitute for formal privacy.

↑