发表机构
Koç University; Bilkent University(科奇大学; 比尔肯特大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
HE-OFT提出首个无需任何一方获得训练模型的密码学安全一次性联邦微调协议,通过同态加密组合加密头部位移,在保持高准确率的同时显著降低通信开销。
AI 中文摘要
许多组织通过在私有数据上进行微调,使大型预训练模型适应其自身任务。这些参与方中,多方往往持有同一任务的数据,并希望在不必汇集数据的情况下共同微调模型。联邦学习(FL)支持联合微调,但对共享中间值(模型或其梯度)的重构攻击仍然构成隐私风险。一种交换单个加密贡献的一次性协议不会暴露任何中间值。然而,此类协议仍会将训练后的模型分发给每个参与者,这在模型属于受监管或专有资产的情况下是不被允许的。我们提出HE-OFT,这是首个无需任何一方获得训练模型的密码学安全的一次性联邦微调协议。每个客户端在冻结的公共骨干网络上微调一个低秩适配器和一个分类头,并保留适配器。客户端上传一个加密的头部位移,服务器在多参与方CKKS下进行组合,且从不解密。客户端中的法定人数仅向查询者返回预测标签。在四个文本分类任务和一个视觉任务上,HE-OFT达到61%至79%的准确率,而单独训练的客户端仅为20%至48%。HE-OFT保持了公开模型准确率的85%至96%。测试时查询在单核上耗时443.1至1713.1秒,或在GPU上通过层级恢复耗时56.1至255.1秒。在服务器端恢复层级可将每次查询的流量从最高1.6 GiB降至13.5 MiB。
英文摘要
Many organizations adapt large pretrained models to their own tasks by fine-tuning on private data. Several of these parties often hold data for the same task and wish to fine-tune a model together without pooling that data. Federated learning (FL) enables joint fine-tuning, but reconstruction attacks on shared intermediate values (the model or its gradients) remain a privacy risk. A one-shot protocol that exchanges one encrypted contribution exposes no intermediate value. Such a protocol still gives the trained model to every participant, which is not permitted where the model is a regulated or proprietary asset. We present HE-OFT, the first cryptographically secure one-shot federated fine-tuning protocol in which no party receives the trained model. Each client fine-tunes a low-rank adapter and a classifier head on a frozen public backbone and keeps the adapter. The client uploads one encrypted head displacement, which the server combines under multiparty CKKS and never decrypts. A quorum of clients returns only the predicted label to the querier. On four text classification tasks and one vision task, HE-OFT reaches 61 to 79 per cent accuracy, against 20 to 48 per cent for a client training alone. HE-OFT keeps 85 to 96 per cent of the accuracy of a disclosed model. A test-time query takes 443.1 to 1713.1 s on one core, or 56.1 to 255.1 s with level restoration on a GPU. Restoring levels at the server cuts the traffic per query from up to 1.6 GiB to 13.5 MiB.
CommentsTechnical report. 32 pages, 7 figures, 12 tables. Code: CRYPTO-KU/HE-OFT" target="_blank" rel="noopener">https://github.com/CRYPTO-KU/HE-OFT