Learning while Respecting Privacy and Robustness to Adversarial Distributed Datasets

Learning while Respecting Privacy and Robustness to Adversarial Distributed Datasets
复制标题

DOI:
10.23919/eusipco55093.2022.9909977
复制
发表时间:
2022-08
期刊:
2022 30th European Signal Processing Conference (EUSIPCO)
影响因子:
--
通讯作者:
A. Sadeghi;G. Giannakis
A. Sadeghi;G. Giannakis
中科院分区:
其他
文献类型:
--
作者:
A. Sadeghi;G. Giannakis

文献摘要

相似文献

大量数据集通常是在多个站点上分布的,其中可扩展性,数据隐私和完整性以及带宽的缩放性劝阻这些数据通常将这些数据上传到中央服务器,这使所谓的联合学习框架推动了多个工人与服务器交换“集中式”模型,以实现该型号的工具群体或商定的工具。尽管服务器出现,但在此上下文中逐步解决了各种数据分布的范围,在此上下文中,该分布在此上下文。在此目标的数据集中,数据分布是未知的,并围绕着围绕经验数据分布的Wasserstein Ball。小计算开销。使用图像数据集进行数值测试。
Massive datasets are typically distributed geographically across multiple sites, where scalability, data privacy and integrity, as well as bandwidth scarcity typically discourage uploading these data to a central server. This has propelled the so-called federated learning framework where multiple workers exchange information with a server to learn a “centralized” model using data locally generated and/or stored across workers. This learning framework necessitates workers to communicate iteratively with the server. Although appealing for its scalability, one needs to carefully address the various data distribution shifts across workers, which degrades the performance of the learnt model. In this context, the distributionally robust op-timization framework is considered here. The objective is to endow the trained model with robustness against adversarially manipulated input data, or, distributional uncertainties, such as mismatches between training and testing data distributions, or among datasets stored at different workers. To this aim, the data distribution is assumed unknown, and to land within a Wasserstein ball centered around the empirical data distribution. This robust learning task entails an infinite-dimensional optimization problem, which is challenging. Leveraging a strong duality result, a surrogate is obtained, for which a primal-dual algorithm is developed. Compared to classical methods, the proposed algorithm offers robustness with little computational overhead. Numerical tests using image datasets showcase the merits of the proposed algorithm under several existing adversarial attacks and distributional uncertainties.