RecUP-FL: Reconciling Utility and Privacy in Federated learning via User-configurable Privacy Defense

RecUP-FL: Reconciling Utility and Privacy in Federated learning via User-configurable Privacy Defense
复制标题

DOI:
10.1145/3579856.3582819
复制
发表时间:
2023-04
期刊:
Proceedings of the 2023 ACM Asia Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Yue-li Cui;Syed Imran Ali Meerza;Zhuohang Li;Luyang Liu;Jiaxin Zhang;Jian Liu
Yue-li Cui;Syed Imran Ali Meerza;Zhuohang Li;Luyang Liu;Jiaxin Zhang;Jian Liu
中科院分区:
其他
文献类型:
--
作者:
Yue-li Cui;Syed Imran Ali Meerza;Zhuohang Li;Luyang Liu;Jiaxin Zhang;Jian Liu

文献摘要

相似文献

联合学习(FL)通过允许客户在不共享私人数据的情况下协作训练模型来提供各种隐私优势。但是,最近的研究表明,私人信息仍然可以通过共享梯度泄漏。为了进一步最大程度地减少隐私泄漏的风险,现有防御通常要求客户在与服务器共享之前在本地修改其梯度(例如,差异隐私)。尽管这些方法在某些情况下是有效的,但它们将整个数据视为要保护的单个实体,这通常是在模型实用程序中以很大的成本而产生的。在本文中,我们试图通过提出可提供用户可配置的隐私防御recup-fl来调和FL中的实用性和隐私,该防御能力可以更好地专注于用户指定的敏感属性,同时在传统防御方面获得了显着改善的效用。此外,我们观察到现有的推理攻击通常依靠机器学习模型来提取私人信息(例如属性)。因此,我们将这种隐私防御制定为对抗性学习问题,其中recup-fl会产生轻微的扰动,可以在共享以愚弄对手模型之前将其添加到梯度中。为了提高受元学习概念的启发的不可传递的黑盒对手模型的可传递性,recup-fl形成了一个模型动物园,其中包含一组替代模型,并在白色盒子和黑色框的模拟之间进行迭代交替框对面攻击方案,以生成扰动。在各种对抗设置(属性推理攻击和数据重建攻击)下,在四个数据集上进行了广泛的实验表明,recup-fl可以在敏感属性上满足用户指定的隐私约束,同时显着改善模型实用性隐私防御。
Federated learning (FL) provides a variety of privacy advantages by allowing clients to collaboratively train a model without sharing their private data. However, recent studies have shown that private information can still be leaked through shared gradients. To further minimize the risk of privacy leakage, existing defenses usually require clients to locally modify their gradients (e.g., differential privacy) prior to sharing with the server. While these approaches are effective in certain cases, they regard the entire data as a single entity to protect, which usually comes at a large cost in model utility. In this paper, we seek to reconcile utility and privacy in FL by proposing a user-configurable privacy defense, RecUP-FL, that can better focus on the user-specified sensitive attributes while obtaining significant improvements in utility over traditional defenses. Moreover, we observe that existing inference attacks often rely on a machine learning model to extract the private information (e.g., attributes). We thus formulate such a privacy defense as an adversarial learning problem, where RecUP-FL generates slight perturbations that can be added to the gradients before sharing to fool adversary models. To improve the transferability to un-queryable black-box adversary models, inspired by the idea of meta-learning, RecUP-FL forms a model zoo containing a set of substitute models and iteratively alternates between simulations of the white-box and the black-box adversarial attack scenarios to generate perturbations. Extensive experiments on four datasets under various adversarial settings (both attribute inference attack and data reconstruction attack) show that RecUP-FL can meet user-specified privacy constraints over the sensitive attributes while significantly improving the model utility compared with state-of-the-art privacy defenses.