arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Aegis:面向隐私保护医学联邦学习的生成式梯度掩蔽

Aegis: Generative Gradient Masking for Privacy-Preserving Medical Federated Learning

Chaoyu Zhang, Shanghao Shi, Heng Jin, Ning Wang, Y. Thomas Hou, Wenjing Lou

arXiv 2609.38339首次发表:更新:

发表机构

Virginia Tech; Washington University in St. Louis; University of South Florida(弗吉尼亚理工大学; 圣路易斯华盛顿大学; 南佛罗里达大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

Aegis提出一种客户端侧生成式梯度掩蔽防御,通过合成数据扩大有效批量大小,突破模型反演攻击的恢复上限,在不损失模型效用和修改联邦学习协议的前提下,中和多种最先进攻击,为医学联邦学习提供实用隐私保护。

AI 中文摘要

联邦学习(FL)已成为多机构医学AI的基础范式,使医院和研究中心无需交换患者记录即可联合训练诊断模型。然而,这一隐私承诺正日益受到质疑:恶意或诚实但好奇的服务器可以发起模型反演攻击(MIA),直接从共享的模型更新中重建私有患者图像,而近期可扩展的闭式攻击甚至能在临床现实的批量大小下穿透安全聚合。现有防御面临一个令人不满的困境。梯度扰动方法(如差分隐私和剪枝)会牺牲临床可靠性所依赖的诊断准确性,而密码学协议则增加了系统复杂性,却仍使更新暴露于这些可扩展攻击之下。我们提出Aegis,一种原则性的客户端侧防御,在不扰动患者数据或修改FL协议的情况下打破这一困境。我们的关键见解是:每种已知MIA的成功从根本上受限于相对于模型泄漏容量的本地批量大小;一旦超过此限制,不同样本发生碰撞,重建结果坍缩为不可区分的混合体。Aegis将这一普遍瓶颈转化为防御:每个客户端在其真实更新之上叠加一个基于本地合成、任务相关数据计算的掩蔽梯度,刻意将有效批量推至攻击的恢复能力之上。我们辅以标准凸假设下的理论收敛保证,并在MNIST、CIFAR-10以及三种MedMNIST模态(胸部X光、腹部CT、结肠病理)上评估Aegis。Aegis中和了三种最先进的MIA,同时保持模型效用并仅产生适度开销,为医学FL提供了一种实用的隐私原语。

英文摘要

Federated learning (FL) has become a foundational paradigm for multi-institutional medical AI, allowing hospitals and research centers to jointly train diagnostic models without exchanging patient records. This privacy promise, however, is increasingly contested: a malicious or honest-but-curious server can launch model inversion attacks (MIAs) that reconstruct private patient images directly from shared model updates, and recent scalable, closed-form attacks penetrate even secure aggregation at clinically realistic batch sizes. Existing defenses face an unsatisfactory dilemma. Gradient-perturbation methods such as differential privacy and pruning trade away the diagnostic accuracy on which clinical reliability depends, while cryptographic protocols add system complexity yet still leave updates exposed to these scalable attacks. We propose Aegis, a principled client-side defense that breaks this dilemma without perturbing patient data or modifying the FL protocol. Our key insight is that the success of every known MIA is fundamentally bounded by the local batch size relative to the model's leakage capacity; once this limit is exceeded, distinct samples collide and reconstructions collapse into indistinguishable mixtures. Aegis turns this universal bottleneck into a defense: each client superimposes onto its real update a masking gradient computed on locally synthesized, task-relevant data, deliberately pushing the effective batch beyond the attack's recovery capacity. We complement the design with theoretical convergence guarantees under standard convex assumptions and evaluate Aegis on MNIST, CIFAR-10, and three MedMNIST modalities (chest X-ray, abdominal CT, colon pathology). Aegis neutralizes three state-of-the-art MIAs while preserving model utility and incurring only modest overhead, offering a practical privacy primitive for medical FL.

CommentsComments: 10 pages of main text, 4 figures, 2 tables, and 1 algorithm; supplementary material included. Accepted by NeurIPS 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑