FL-Market: Trading Private Models in Federated Learning

FL-Market: Trading Private Models in Federated Learning
复制标题

DOI:
10.1109/bigdata55660.2022.10020232
复制
发表时间:
2021-06
期刊:
2022 IEEE International Conference on Big Data (Big Data)
影响因子:
--
通讯作者:
Shuyuan Zheng;Yang Cao;Masatoshi Yoshikawa;Huizhong Li;Qiang Yan
Shuyuan Zheng;Yang Cao;Masatoshi Yoshikawa;Huizhong Li;Qiang Yan
中科院分区:
其他
文献类型:
--
作者:
Shuyuan Zheng;Yang Cao;Masatoshi Yoshikawa;Huizhong Li;Qiang Yan

文献摘要

相似文献

获取足够数量的训练数据是基于机器学习(ML)的数据分析的重要瓶颈。最近,商品化ML模型被提出作为面向ML的数据采集的一种经济和适度的解决方案。然而,现有的模型市场假设经纪人可以访问数据所有者的私人培训数据,这在实践中可能不现实。在本文中,为了促进ML任务的可信数据获取,我们提出了FL-Market,一个本地私有的模型市场,它不仅保护隐私不受模型买家的攻击,而且保护不受信任的代理的隐私。FL-Market将ML与使用联合学习集中收集经纪人一侧的训练数据的需求分离,联合学习是一种保护隐私的ML范例,其中数据所有者通过上传局部梯度(将被聚合到全局梯度中以进行模型更新)来协作训练ML模型。然后,FL-Market使数据所有者能够通过本地差异隐私来局部扰乱他们的梯度,从而进一步防止隐私风险。为了驱动FL-Market,我们提出了一种深度学习授权的拍卖机制,用于智能地确定局部梯度的扰动程度,以及一种用于聚集扰动梯度的最优聚集机制。我们的拍卖和聚集机制可以联合最大化全局梯度的精度,从而优化模型购买者的效用。实验结果验证了所提机制的有效性。
Acquiring a sufficient amount of training data is a significant bottleneck for machine learning (ML) based data analytics. Recently, commoditizing ML models has been proposed as an economical and moderate solution to ML-oriented data acquisition. However, existing model marketplaces assume that the broker can access data owners’ private training data, which may not be realistic in practice. In this paper, to promote trustworthy data acquisition for ML tasks, we propose FL-Market, a locally private model marketplace that protects privacy against not only model buyers but also an untrusted broker. FL-Market decouples ML from the need to centrally gather training data on the broker’s side using federated learning, a privacy-preserving ML paradigm in which data owners collaboratively train an ML model by uploading local gradients (to be aggregated into a global gradient for model updating). Then, FL-Market enables data owners to locally perturb their gradients by local differential privacy and thus further prevents privacy risks. To drive FL-Market, we propose a deep learning-empowered auction mechanism for intelligently deciding the local gradients’ perturbation levels and an optimal aggregation mechanism for aggregating the perturbed gradients. Our auction and aggregation mechanisms can jointly maximize the global gradient’s accuracy, which optimizes model buyers’ utility. Our experiments verify the effectiveness of the proposed mechanisms.