Revisiting Gradient Pruning: A Dual Realization for Defending against Gradient Attacks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Xue, Lulu, Hu, Shengshan, Zhao, Ruizhi, Zhang, Leo Yu, Hu, Shengqing, Sun, Lichao, Yao, Dezhong
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866914659022405632
author Xue, Lulu
Hu, Shengshan
Zhao, Ruizhi
Zhang, Leo Yu
Hu, Shengqing
Sun, Lichao
Yao, Dezhong
author_facet Xue, Lulu
Hu, Shengshan
Zhao, Ruizhi
Zhang, Leo Yu
Hu, Shengqing
Sun, Lichao
Yao, Dezhong
contents Collaborative learning (CL) is a distributed learning framework that aims to protect user privacy by allowing users to jointly train a model by sharing their gradient updates only. However, gradient inversion attacks (GIAs), which recover users' training data from shared gradients, impose severe privacy threats to CL. Existing defense methods adopt different techniques, e.g., differential privacy, cryptography, and perturbation defenses, to defend against the GIAs. Nevertheless, all current defense methods suffer from a poor trade-off between privacy, utility, and efficiency. To mitigate the weaknesses of existing solutions, we propose a novel defense method, Dual Gradient Pruning (DGP), based on gradient pruning, which can improve communication efficiency while preserving the utility and privacy of CL. Specifically, DGP slightly changes gradient pruning with a stronger privacy guarantee. And DGP can also significantly improve communication efficiency with a theoretical analysis of its convergence and generalization. Our extensive experiments show that DGP can effectively defend against the most powerful GIAs and reduce the communication cost without sacrificing the model's utility.
format Preprint
id arxiv_https___arxiv_org_abs_2401_16687
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Revisiting Gradient Pruning: A Dual Realization for Defending against Gradient Attacks
Xue, Lulu
Hu, Shengshan
Zhao, Ruizhi
Zhang, Leo Yu
Hu, Shengqing
Sun, Lichao
Yao, Dezhong
Cryptography and Security
Machine Learning
Collaborative learning (CL) is a distributed learning framework that aims to protect user privacy by allowing users to jointly train a model by sharing their gradient updates only. However, gradient inversion attacks (GIAs), which recover users' training data from shared gradients, impose severe privacy threats to CL. Existing defense methods adopt different techniques, e.g., differential privacy, cryptography, and perturbation defenses, to defend against the GIAs. Nevertheless, all current defense methods suffer from a poor trade-off between privacy, utility, and efficiency. To mitigate the weaknesses of existing solutions, we propose a novel defense method, Dual Gradient Pruning (DGP), based on gradient pruning, which can improve communication efficiency while preserving the utility and privacy of CL. Specifically, DGP slightly changes gradient pruning with a stronger privacy guarantee. And DGP can also significantly improve communication efficiency with a theoretical analysis of its convergence and generalization. Our extensive experiments show that DGP can effectively defend against the most powerful GIAs and reduce the communication cost without sacrificing the model's utility.
title Revisiting Gradient Pruning: A Dual Realization for Defending against Gradient Attacks
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2401.16687