<p>Federated learning (FL) is a promising paradigm for collaboratively training models across distributed clients while retaining data locally. Recent studies have revealed that traditional FL methods may inadvertently expose sensitive information through shared local updates or global model parameters. Local differential privacy (LDP), a robust and well-defined privacy mechanism, has been widely adopted to protect sensitive data during collection. Despite its effectiveness, integrating LDP into FL poses significant challenges, particularly due to the curse of dimensionality. Existing solutions for the problem mostly rely on dimension reduction techniques that sample important dimensions from the model based on a pre-defined number of dimensions. However, this approach usually allocates the privacy budget across sampled dimensions and ignores the difference of parameter layers, leading to degraded model performance. To overcome these limitations, we present AdaS-FLDP, a novel framework that adaptively sparsifies parameters while ensuring differential privacy. The core of AdaS-FLDP is a novel dimension-adaptive mechanism that (i) exploits a non-trivial analysis on the model features and (ii) enables us to select important dimensions comprehensively, without the splitting of privacy budget. Furthermore, AdaS-FLDP incorporates a utility-enhanced piecewise mechanism to effectively perturb the values of selected dimensions. Extensive experiments demonstrate that the AdaS-FLDP achieves a superior balance among privacy protection, model performance, and communication efficiency.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

AdaS-FLDP: local differentially private federated learning with adaptive sparsification

  • Chen Huang,
  • Yanhui Li,
  • Yuxin Zhao,
  • Xinjie Du,
  • Junqing Huang

摘要

Federated learning (FL) is a promising paradigm for collaboratively training models across distributed clients while retaining data locally. Recent studies have revealed that traditional FL methods may inadvertently expose sensitive information through shared local updates or global model parameters. Local differential privacy (LDP), a robust and well-defined privacy mechanism, has been widely adopted to protect sensitive data during collection. Despite its effectiveness, integrating LDP into FL poses significant challenges, particularly due to the curse of dimensionality. Existing solutions for the problem mostly rely on dimension reduction techniques that sample important dimensions from the model based on a pre-defined number of dimensions. However, this approach usually allocates the privacy budget across sampled dimensions and ignores the difference of parameter layers, leading to degraded model performance. To overcome these limitations, we present AdaS-FLDP, a novel framework that adaptively sparsifies parameters while ensuring differential privacy. The core of AdaS-FLDP is a novel dimension-adaptive mechanism that (i) exploits a non-trivial analysis on the model features and (ii) enables us to select important dimensions comprehensively, without the splitting of privacy budget. Furthermore, AdaS-FLDP incorporates a utility-enhanced piecewise mechanism to effectively perturb the values of selected dimensions. Extensive experiments demonstrate that the AdaS-FLDP achieves a superior balance among privacy protection, model performance, and communication efficiency.