On Differential Privacy for Wireless Federated Learning with Non-coherent Aggregation

On Differential Privacy for Wireless Federated Learning with Non-coherent Aggregation
复制标题

DOI:
10.1109/globecom54140.2023.10437931
复制
发表时间:
2023-12
期刊:
GLOBECOM 2023 - 2023 IEEE Global Communications Conference
影响因子:
--
通讯作者:
Mohamed Seif;Alphan Șahin;H. V. Poor;Andrea J. Goldsmith
Mohamed Seif;Alphan Șahin;H. V. Poor;Andrea J. Goldsmith
中科院分区:
其他
文献类型:
--
作者:
Mohamed Seif;Alphan Șahin;H. V. Poor;Andrea J. Goldsmith

文献摘要

相似文献

在本文中,我们研究了在局部差分隐私约束下通过多数投票、符号随机梯度下降(signSGD)以及无线计算(OAC)进行的分布式训练。在我们的方法中,用户首先剪切局部随机梯度并注入一定量的噪声作为隐私增强策略。随后,他们根据扰动的局部随机梯度的符号激活 OFDM 子载波的索引,以在参数服务器上实现基于频移键控的多数投票计算。我们评估了所提出方法的隐私优势,并从理论上描述了每个用户隐私泄露的特征。我们的结果表明,由于无线信道的叠加特性,所提出的技术提高了隐私保证,并将泄漏限制在 $\mathcal{O}(1/\sqrt{K})$ 的缩放因子,其中 $K$ 是用户数量。通过数值实验,我们表明,当两种方法引入相同的隐私增强策略时,所提出的非相干聚合在时间同步误差下的学习精度优于基于正交相移键控的相干聚合,即一位数字聚合(OBDA)。
In this paper, we study distributed training by majority vote with the sign stochastic gradient descent (signSGD) along with over-the-air computation (OAC) under local differential privacy constraints. In our approach, the users first clip the local stochastic gradients and inject a certain amount of noise as a privacy enhancement strategy. Subsequently, they activate the indices of OFDM subcarriers based on the signs of the perturbed local stochastic gradients to realize a frequency-shift-keying-based majority vote computation at the parameter server. We evaluate the privacy benefits of the proposed approach and characterize the per-user privacy leakage theoretically. Our results show that the proposed technique improves the privacy guarantees and limits the leakage to a scaling factor of $\mathcal{O}(1/\sqrt{K})$, where $K$ is the number of users, thanks to the superposition property of the wireless channel. With numerical experiments, we show that the proposed non-coherent aggregation is superior to quadrature-phase-shift-keying-based coherent aggregation, namely, one-bit digital aggregation (OBDA), in learning accuracy under time synchronization errors when the same privacy enhancement strategy is introduced to both methods.