From the Perspective of Prototypes: A Privacy-Preserving Personalized Federated Learning Framework
摘要
Federated learning, as a collaborative learning approach that protects user privacy, has garnered significant attention from researchers in recent years. However, traditional federated learning paradigm generally suffers from two major limitations: ubiquitous reliance on the IID assumption and the homogeneous architecture design of local model and global model. In contrast, prototype federated learning, a personalize federated learning (PFL) paradigm, addresses these heterogeneity problem quite well. However, its original paradigm ignores privacy risks posed by prototype leakage. To prove the risk of prototype leakage, we propose a generative attack method based on conditional generative models, using prototype information to achieve sample reconstruction and theft of training results. To the best of our knowledge, we demonstrate for the first time that prototype information leakage can lead to a series of privacy security issues. Furthermore, We propose a privacy-preserving personalized federated learning framework based on prototypes, ingeniously integrating homomorphic encryption technology into the training of prototype federated learning through equivalent transformations, thus addressing the privacy issue in prototype federated learning.