Privacy Threat and Defense for Federated Learning With Non-i.i.d. Data in AIoT

Privacy Threat and Defense for Federated Learning With Non-i.i.d. Data in AIoT
复制标题

DOI:
10.1109/tii.2021.3073925
复制
发表时间:
2022-02-01
影响因子:
12.3
通讯作者:
Li, Wei
Li, Wei
中科院分区:
计算机科学1区
文献类型:
--
作者:
Xiong, Zuobin;Cai, Zhipeng;Li, Wei

文献摘要

被引文献

相似文献

根据处理大量数据,提供高质量服务以及保护事物人工智能(AIOT)的用户隐私的需求,联合学习(FL)被视为一种有前途的技术,可促进具有隐私保护的分布式学习。尽管开发保护隐私的FL的重要性吸引了很多关注,但现有的研究仅着眼于具有独立分布的数据(I.I.D.)数据,并且缺乏对非I.I.D的研究。设想。更糟糕的是,I.I.D.的假设数据是不切实际的,可以降低实际应用中隐私保护的性能。在本文中,我们使用非i.i.D进行了对佛罗里达州隐私保护的创新探索。数据。首先,对FL的隐私泄漏进行了彻底的分析,并证明了隐私推理攻击的性能上限。基于我们的分析,一种新颖的算法2DP-FL旨在通过在训练本地模型和分发全球模型时添加噪声来实现差异隐私。特别是,我们的2DP-FL算法具有增加噪声的灵活性,可以满足各种需求,并且具有收敛的上限。最后,真正的数据实验可以验证我们的主题分析结果以及2DP-FL在隐私保护,学习收敛和模型准确性方面的优势。
Under the needs of processing huge amounts of data, providing high-quality service, and protecting user privacy in artificial intelligence of things (AIoT), federated learning (FL) has been treated as a promising technique to facilitate distributed learning with privacy protection. Although the importance of developing privacy-preserving FL has attracted a lot of attentions, the existing research only focuses on FL with independent identically distributed (i.i.d.) data and lacks study of non-i.i.d. scenario. What is worse, the assumption of i.i.d. data is impractical, reducing the performance of privacy protection in real applications. In this article, we carry out an innovative exploration of privacy protection in FL with non-i.i.d. data. First, a thorough analysis on privacy leakage in FL is conducted with proving the performance upper bound of privacy inference attack. Based on our analysis, a novel algorithm, 2DP-FL, is designed to achieve differential privacy by adding noise during training local models and when distributing global model. Especially, our 2DP-FL algorithm has a flexibility of noise addition to meet various needs and has a convergence upper bound. Finally, the real-data experiments can validate the results of our the oretical analysis and the advantages of 2DP-FL in privacy protection, learning convergence, and model accuracy.