A Game-theoretic Framework for Privacy-preserving Federated Learning

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Zhang, Xiaojin, Fan, Lixin, Wang, Siwei, Li, Wenjie, Chen, Kai, Yang, Qiang
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909122635497472
author Zhang, Xiaojin
Fan, Lixin
Wang, Siwei
Li, Wenjie
Chen, Kai
Yang, Qiang
author_facet Zhang, Xiaojin
Fan, Lixin
Wang, Siwei
Li, Wenjie
Chen, Kai
Yang, Qiang
contents In federated learning, benign participants aim to optimize a global model collaboratively. However, the risk of \textit{privacy leakage} cannot be ignored in the presence of \textit{semi-honest} adversaries. Existing research has focused either on designing protection mechanisms or on inventing attacking mechanisms. While the battle between defenders and attackers seems never-ending, we are concerned with one critical question: is it possible to prevent potential attacks in advance? To address this, we propose the first game-theoretic framework that considers both FL defenders and attackers in terms of their respective payoffs, which include computational costs, FL model utilities, and privacy leakage risks. We name this game the federated learning privacy game (FLPG), in which neither defenders nor attackers are aware of all participants' payoffs. To handle the \textit{incomplete information} inherent in this situation, we propose associating the FLPG with an \textit{oracle} that has two primary responsibilities. First, the oracle provides lower and upper bounds of the payoffs for the players. Second, the oracle acts as a correlation device, privately providing suggested actions to each player. With this novel framework, we analyze the optimal strategies of defenders and attackers. Furthermore, we derive and demonstrate conditions under which the attacker, as a rational decision-maker, should always follow the oracle's suggestion \textit{not to attack}.
format Preprint
id arxiv_https___arxiv_org_abs_2304_05836
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle A Game-theoretic Framework for Privacy-preserving Federated Learning
Zhang, Xiaojin
Fan, Lixin
Wang, Siwei
Li, Wenjie
Chen, Kai
Yang, Qiang
Machine Learning
Artificial Intelligence
Cryptography and Security
Computer Science and Game Theory
In federated learning, benign participants aim to optimize a global model collaboratively. However, the risk of \textit{privacy leakage} cannot be ignored in the presence of \textit{semi-honest} adversaries. Existing research has focused either on designing protection mechanisms or on inventing attacking mechanisms. While the battle between defenders and attackers seems never-ending, we are concerned with one critical question: is it possible to prevent potential attacks in advance? To address this, we propose the first game-theoretic framework that considers both FL defenders and attackers in terms of their respective payoffs, which include computational costs, FL model utilities, and privacy leakage risks. We name this game the federated learning privacy game (FLPG), in which neither defenders nor attackers are aware of all participants' payoffs. To handle the \textit{incomplete information} inherent in this situation, we propose associating the FLPG with an \textit{oracle} that has two primary responsibilities. First, the oracle provides lower and upper bounds of the payoffs for the players. Second, the oracle acts as a correlation device, privately providing suggested actions to each player. With this novel framework, we analyze the optimal strategies of defenders and attackers. Furthermore, we derive and demonstrate conditions under which the attacker, as a rational decision-maker, should always follow the oracle's suggestion \textit{not to attack}.
title A Game-theoretic Framework for Privacy-preserving Federated Learning
topic Machine Learning
Artificial Intelligence
Cryptography and Security
Computer Science and Game Theory
url https://arxiv.org/abs/2304.05836