错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Membership Privacy Protection for Federated Learning in Web 3.0

  • Meng Shen,
  • Xiangyun Tang,
  • Wei Wang,
  • Liehuang Zhu

摘要

In recent years, the emergence of Web 3.0 has been fueled by its emphasis on data ownership and the use of data value. In the Web 3.0 era, data control is returned to users, with data being recognized as their personal asset. However, despite this shift, privacy leakage issues persist in intelligent computing, posing potential risks to users’ interests. Federated Learning (FL), as a popular distributed learning framework, has gained traction due to its ability to train models collaboratively without the need to share raw data, only requiring parameter sharing. Nonetheless, FL is not impervious to emerging threats, such as membership inference attacks, which pose significant risks to the privacy of data assets owned by users. In this chapter, we present a defense mechanism to prevent membership privacy leakage from local models and global models in the training phase and prediction phase of Federated Learning, respectively, while maintaining high model utility. Deploying two key components, i.e., parameter filter and noise generator, our scheme selects relevant model parameters and adds crafted pruning perturbations to local models at each round of FL. The model accuracy, defense effectiveness, and time efficiency of our scheme have been verified with a large number of experiments.