Differential Privacy in Federated Dynamic Gradient Clipping Based on Gradient Norm
摘要
Federal learning achieves privacy preservation by adding noise to gradient. The noise needs to be clipped to prevent excessive noise from significantly affecting the accuracy of models. However, the imprecise clipped threshold affects the amount of gradient noise leading to degradation of model accuracy. In this paper, for reducing the impact of gradient noise on model accuracy, we propose a differential privacy in federated dynamic gradient clipping based on gradient norm method named DP-FedDGCN. DP-FedDGCN reduces the impact of the amount of gradient noise on the accuracy of the model by dynamically generating a clipped threshold to crop the gradients, achieving the trade-off between data protection and model accuracy. The experimental results show that the attacked accuracy remains consistent in the case of Dirichlet distribution parameters \(\alpha =1\) , using MIA, ML-Leaks, and White-box inference attacks. Meanwhile, the average test accuracy outperforms the DP-FedAvg, DP-FedAGNC, and DP-FedDDC methods by about 2.46%, 1.07%, and 1.09%.