错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Verifiable Privacy-Preserving Federated Learning in Web 3.0

  • Meng Shen,
  • Xiangyun Tang,
  • Wei Wang,
  • Liehuang Zhu

摘要

Web 3.0 emphasizes the decentralization of data assets to build a more open, trustworthy, and user-empowered data ecosystem. Therefore, users have complete sovereignty and ownership over their data in Web 3.0. However, the high degree of personal control over data limits the mobility and interoperability of data, forming data silos that restrict the development of Web 3.0. As an advanced paradigm that breaks down data silos, federated learning can promote collaborative sharing of data assets while protecting user privacy. However, in the open and complex environment of Web 3.0, federated learning is vulnerable to attacks. In the Web 3.0 environment, inquisitive servers and clients might exploit global models to conduct passive inference assaults, aiming to illicitly acquire data assets from training data. Additionally, the global model also faces the threat of malicious clients launching active inference attacks and submitting false local gradients. We introduce PILE, a resilient framework for federated learning that safeguards the confidentiality of both local gradients and global models. Furthermore, it guarantees their integrity through the verification of gradients. In PILE, we propose a scheme for gradient validation using local gradients. It includes two components of zero-knowledge proof so that the local gradient and global model do not need to be publicly disclosed. In addition, we have demonstrated the security of PILE and conducted experimental evaluations of the scheme under both active and passive inference attacks. The experiment results show that PILE can provide strong privacy protection and model training robustness for data assets in Web 3.0.