Federated learning, as a collaborative learning approach that protects user privacy, has garnered significant attention from researchers in recent years. However, traditional federated learning paradigm generally suffers from two major limitations: ubiquitous reliance on the IID assumption and the homogeneous architecture design of local model and global model. In contrast, prototype federated learning, a personalize federated learning (PFL) paradigm, addresses these heterogeneity problem quite well. However, its original paradigm ignores privacy risks posed by prototype leakage. To prove the risk of prototype leakage, we propose a generative attack method based on conditional generative models, using prototype information to achieve sample reconstruction and theft of training results. To the best of our knowledge, we demonstrate for the first time that prototype information leakage can lead to a series of privacy security issues. Furthermore, We propose a privacy-preserving personalized federated learning framework based on prototypes, ingeniously integrating homomorphic encryption technology into the training of prototype federated learning through equivalent transformations, thus addressing the privacy issue in prototype federated learning.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

From the Perspective of Prototypes: A Privacy-Preserving Personalized Federated Learning Framework

  • Liwei Liu,
  • Zijian Liu,
  • Na Ruan

摘要

Federated learning, as a collaborative learning approach that protects user privacy, has garnered significant attention from researchers in recent years. However, traditional federated learning paradigm generally suffers from two major limitations: ubiquitous reliance on the IID assumption and the homogeneous architecture design of local model and global model. In contrast, prototype federated learning, a personalize federated learning (PFL) paradigm, addresses these heterogeneity problem quite well. However, its original paradigm ignores privacy risks posed by prototype leakage. To prove the risk of prototype leakage, we propose a generative attack method based on conditional generative models, using prototype information to achieve sample reconstruction and theft of training results. To the best of our knowledge, we demonstrate for the first time that prototype information leakage can lead to a series of privacy security issues. Furthermore, We propose a privacy-preserving personalized federated learning framework based on prototypes, ingeniously integrating homomorphic encryption technology into the training of prototype federated learning through equivalent transformations, thus addressing the privacy issue in prototype federated learning.