A New Federated Learning Framework Against Gradient Inversion Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Guo, Pengxin, Zeng, Shuang, Chen, Wenhao, Zhang, Xiaodan, Ren, Weihong, Zhou, Yuyin, Qu, Liangqiong
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910737428905984
author Guo, Pengxin
Zeng, Shuang
Chen, Wenhao
Zhang, Xiaodan
Ren, Weihong
Zhou, Yuyin
Qu, Liangqiong
author_facet Guo, Pengxin
Zeng, Shuang
Chen, Wenhao
Zhang, Xiaodan
Ren, Weihong
Zhou, Yuyin
Qu, Liangqiong
contents Federated Learning (FL) aims to protect data privacy by enabling clients to collectively train machine learning models without sharing their raw data. However, recent studies demonstrate that information exchanged during FL is subject to Gradient Inversion Attacks (GIA) and, consequently, a variety of privacy-preserving methods have been integrated into FL to thwart such attacks, such as Secure Multi-party Computing (SMC), Homomorphic Encryption (HE), and Differential Privacy (DP). Despite their ability to protect data privacy, these approaches inherently involve substantial privacy-utility trade-offs. By revisiting the key to privacy exposure in FL under GIA, which lies in the frequent sharing of model gradients that contain private data, we take a new perspective by designing a novel privacy preserve FL framework that effectively ``breaks the direct connection'' between the shared parameters and the local private data to defend against GIA. Specifically, we propose a Hypernetwork Federated Learning (HyperFL) framework that utilizes hypernetworks to generate the parameters of the local model and only the hypernetwork parameters are uploaded to the server for aggregation. Theoretical analyses demonstrate the convergence rate of the proposed HyperFL, while extensive experimental results show the privacy-preserving capability and comparable performance of HyperFL. Code is available at https://github.com/Pengxin-Guo/HyperFL.
format Preprint
id arxiv_https___arxiv_org_abs_2412_07187
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle A New Federated Learning Framework Against Gradient Inversion Attacks
Guo, Pengxin
Zeng, Shuang
Chen, Wenhao
Zhang, Xiaodan
Ren, Weihong
Zhou, Yuyin
Qu, Liangqiong
Machine Learning
Cryptography and Security
Federated Learning (FL) aims to protect data privacy by enabling clients to collectively train machine learning models without sharing their raw data. However, recent studies demonstrate that information exchanged during FL is subject to Gradient Inversion Attacks (GIA) and, consequently, a variety of privacy-preserving methods have been integrated into FL to thwart such attacks, such as Secure Multi-party Computing (SMC), Homomorphic Encryption (HE), and Differential Privacy (DP). Despite their ability to protect data privacy, these approaches inherently involve substantial privacy-utility trade-offs. By revisiting the key to privacy exposure in FL under GIA, which lies in the frequent sharing of model gradients that contain private data, we take a new perspective by designing a novel privacy preserve FL framework that effectively ``breaks the direct connection'' between the shared parameters and the local private data to defend against GIA. Specifically, we propose a Hypernetwork Federated Learning (HyperFL) framework that utilizes hypernetworks to generate the parameters of the local model and only the hypernetwork parameters are uploaded to the server for aggregation. Theoretical analyses demonstrate the convergence rate of the proposed HyperFL, while extensive experimental results show the privacy-preserving capability and comparable performance of HyperFL. Code is available at https://github.com/Pengxin-Guo/HyperFL.
title A New Federated Learning Framework Against Gradient Inversion Attacks
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2412.07187