Practical Differentially Private and Byzantine-resilient Federated Learning

Author:

Xiang Zihang1ORCID,Wang Tianhao2ORCID,Lin Wanyu3ORCID,Wang Di1ORCID

Affiliation:

1. King Abdullah University of Science and Technology, Thuwal, Saudi Arabia

2. University of Virginia, Charlottesville, VA, USA

3. The Hong Kong Polytechnic University, Hong Kong, China

Abstract

Privacy and Byzantine resilience are two indispensable requirements for a federated learning (FL) system. Although there have been extensive studies on privacy and Byzantine security in their own track, solutions that consider both remain sparse. This is due to difficulties in reconciling privacy-preserving and Byzantine-resilient algorithms. In this work, we propose a solution to such a two-fold issue. We use our version of differentially private stochastic gradient descent (DP-SGD) algorithm to preserve privacy and then apply our Byzantine-resilient algorithms. We note that while existing works follow this general approach, an in-depth analysis on the interplay between DP and Byzantine resilience has been ignored, leading to unsatisfactory performance. Specifically, for the random noise introduced by DP, previous works strive to reduce its seemingly detrimental impact on the Byzantine aggregation. In contrast, we leverage the random noise to construct a first-stage aggregation that effectively rejects many existing Byzantine attacks. Moreover, based on another property of our DP variant, we form a second-stage aggregation which provides a final sound filtering. Our protocol follows the principle of co-designing both DP and Byzantine resilience. We provide both theoretical proof and empirical experiments to show our protocol is effective: retaining high accuracy while preserving the DP guarantee and Byzantine resilience. Compared with the previous work, our protocol 1) achieves significantly higher accuracy even in a high privacy regime; 2) works well even when up to 90% distributive workers are Byzantine.

Funder

National Science Foundation

KAUST-SDAIA Center of Excellence in Data Science and Artificial Intelligence

Publisher

Association for Computing Machinery (ACM)

Reference79 articles.

1. Deep Learning with Differential Privacy

2. Naman Agarwal , Peter Kairouz , and Ziyu Liu . 2021. The skellam mechanism for differentially private federated learning. Advances in Neural Information Processing Systems 34 ( 2021 ). Naman Agarwal, Peter Kairouz, and Ziyu Liu. 2021. The skellam mechanism for differentially private federated learning. Advances in Neural Information Processing Systems 34 (2021).

3. Rohan Anil , Badih Ghazi , Vineet Gupta , Ravi Kumar , and Pasin Manurangsi . 2021. Large-scale differentially private bert. arXiv preprint arXiv:2108.01624 ( 2021 ). Rohan Anil, Badih Ghazi, Vineet Gupta, Ravi Kumar, and Pasin Manurangsi. 2021. Large-scale differentially private bert. arXiv preprint arXiv:2108.01624 (2021).

4. Three Variants of Differential Privacy: Lossless Conversion and Applications

5. Eugene Bagdasaryan , Andreas Veit , Yiqing Hua , Deborah Estrin , and Vitaly Shmatikov . 2020 . How to backdoor federated learning . In International Conference on Artificial Intelligence and Statistics. PMLR, 2938--2948 . Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In International Conference on Artificial Intelligence and Statistics. PMLR, 2938--2948.

Cited by 3 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. A Survey for Federated Learning Evaluations: Goals and Measures;IEEE Transactions on Knowledge and Data Engineering;2024-10

2. Distributed Learning for Large-Scale Models at Edge With Privacy Protection;IEEE Transactions on Computers;2024-04

3. Secure Model Aggregation Against Poisoning Attacks for Cross-Silo Federated Learning With Robustness and Fairness;IEEE Transactions on Information Forensics and Security;2024

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3