Flamingo: Multi-Round Single-Server Secure Aggregation with Applications to Private Federated Learning

Flamingo: Multi-Round Single-Server Secure Aggregation with Applications to Private Federated Learning
复制标题

DOI:
10.1109/sp46215.2023.10179434
复制
发表时间:
2023-05
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Yiping Ma;Jess Woods;Sebastian Angel;Antigoni Polychroniadou;T. Rabin
Yiping Ma;Jess Woods;Sebastian Angel;Antigoni Polychroniadou;T. Rabin
中科院分区:
其他
文献类型:
--
作者:
Yiping Ma;Jess Woods;Sebastian Angel;Antigoni Polychroniadou;T. Rabin

文献摘要

被引文献

相似文献

本文介绍了Flamingo,一个跨大量客户端的数据安全聚合系统。在安全聚合中,服务器对客户端的私有输入进行求和,并获得结果,而不需要学习任何关于单个输入的信息,而不仅仅是最终总和所暗示的信息。Flamingo专注于联邦学习中的多轮设置,其中执行模型权重的许多连续求和(平均值)以获得良好的模型。以前的协议,如Bell等人(CCS '20),是为单轮设计的,并通过多次重复协议来适应联邦学习设置。Flamingo消除了以前协议的每轮设置的需要,并具有新的轻量级辍学弹性协议,以确保如果客户端在总和中间离开,服务器仍然可以获得有意义的结果。此外,Flamingo引入了一种新的方法来本地选择Bell等人引入的所谓客户端邻域。这些技术帮助Flamingo减少了客户端和服务器之间的交互次数,导致在一个完整的训练会话的端到端的运行时间比以前的工作显着减少。我们实现和评估Flamingo,并表明它可以安全地训练神经网络上的(扩展)MNIST和CIFAR-100数据集,与非私有联邦学习系统相比,该模型收敛而不损失准确性。
This paper introduces Flamingo, a system for secure aggregation of data across a large set of clients. In secure aggregation, a server sums up the private inputs of clients and obtains the result without learning anything about the individual inputs beyond what is implied by the final sum. Flamingo focuses on the multi-round setting found in federated learning in which many consecutive summations (averages) of model weights are performed to derive a good model. Previous protocols, such as Bell et al. (CCS ’20), have been designed for a single round and are adapted to the federated learning setting by repeating the protocol multiple times. Flamingo eliminates the need for the per-round setup of previous protocols, and has a new lightweight dropout resilience protocol to ensure that if clients leave in the middle of a sum the server can still obtain a meaningful result. Furthermore, Flamingo introduces a new way to locally choose the so-called client neighborhood introduced by Bell et al. These techniques help Flamingo reduce the number of interactions between clients and the server, resulting in a significant reduction in the end-to-end runtime for a full training session over prior work.We implement and evaluate Flamingo and show that it can securely train a neural network on the (Extended) MNIST and CIFAR-100 datasets, and the model converges without a loss in accuracy, compared to a non-private federated learning system.