In the era of big data, data privacy and security are highly valued, leading to the phenomenon of “data islands”, which hinders the effective utilization of data. Federated learning, as a privacy-preserving distributed machine learning method, allows model training without sharing raw data, addressing the privacy concerns in cross-organizational data cooperation. Although federated learning protects data privacy, participants’ gradient parameters can still potentially leak sensitive information. As a result, extensive research has focused on conducting federated learning while protecting the privacy of gradient parameters and reducing the communication and computational overhead for participants. These efforts assume that each participant adheres honestly to the protocol; however, malicious submissions of incorrect gradient parameters can significantly bias the federated learning model. This paper proposes a federated learning scheme for privacy-protected gradient aggregation and poison detection that defends against malicious poisoning attacks while safeguarding data privacy, and optimizes computational and communication overheads. By employing inner product triples, the computation process is further optimized, enhancing system performance. The security of the scheme is demonstrated, and its efficiency is validated through practical tests, showing that the optimized solution significantly outperforms the basic scheme in terms of performance.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Membership Data Privacy Protection and Poisoning Detection Scheme for Federated Learning

  • Yafeng Li,
  • Zhijun Sun,
  • Lichuan Ma

摘要

In the era of big data, data privacy and security are highly valued, leading to the phenomenon of “data islands”, which hinders the effective utilization of data. Federated learning, as a privacy-preserving distributed machine learning method, allows model training without sharing raw data, addressing the privacy concerns in cross-organizational data cooperation. Although federated learning protects data privacy, participants’ gradient parameters can still potentially leak sensitive information. As a result, extensive research has focused on conducting federated learning while protecting the privacy of gradient parameters and reducing the communication and computational overhead for participants. These efforts assume that each participant adheres honestly to the protocol; however, malicious submissions of incorrect gradient parameters can significantly bias the federated learning model. This paper proposes a federated learning scheme for privacy-protected gradient aggregation and poison detection that defends against malicious poisoning attacks while safeguarding data privacy, and optimizes computational and communication overheads. By employing inner product triples, the computation process is further optimized, enhancing system performance. The security of the scheme is demonstrated, and its efficiency is validated through practical tests, showing that the optimized solution significantly outperforms the basic scheme in terms of performance.