Personalized Privacy-Preserving Federated Learning

被引:0
作者
Boscher, Cedric [1 ]
Benarba, Nawel [1 ]
Elhattab, Fatima [1 ]
Bouchenak, Sara [1 ]
机构
[1] INSA Lyon LIRIS, Lyon, France
来源
PROCEEDINGS OF THE TWENTY-FIFTH ACM INTERNATIONAL MIDDLEWARE CONFERENCE, MIDDLEWARE 2024 | 2024年
关键词
Federated Learning; Privacy Protection; Membership Inference Attacks;
D O I
10.1145/3652892.3700785
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Federated Learning (FL) enables collaborative model training among several participants while keeping local data private. However, FL remains vulnerable to privacy membership inference attacks (MIAs) that allow adversaries to deduce confidential information about participants' training data. Existing defense mechanisms against MIAs compromise model performance and utility, and incur significant overheads. In this paper, we propose DINAR, a novel FL middleware for privacy-preserving neural networks that precisely handles these issues. DINAR leverages personalized FL and follows a fine-grained approach that specifically tackles FL neural network layers that leak more private information than other layers, thus, efficiently protecting FL model against MIAs in a non-intrusive way, while compensating for any potential loss in the model accuracy. The paper presents our extensive empirical evaluation of DINAR, conducted with six widely used datasets, four neural networks, and comparing against five state-of-the-art FL privacy protection mechanisms. The evaluation results show that DINAR reduces the membership inference attack success rate to reach its optimal value, without hurting model accuracy, and without inducing computational overhead. In contrast, existing FL defense mechanisms incur an overhead of up to +35% and +3,000% on respectively FL clientside and FL server-side computation times.
引用
收藏
页码:454 / 466
页数:13
相关论文
共 54 条
[1]   Deep Learning with Differential Privacy [J].
Abadi, Martin ;
Chu, Andy ;
Goodfellow, Ian ;
McMahan, H. Brendan ;
Mironov, Ilya ;
Talwar, Kunal ;
Zhang, Li .
CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, :308-318
[2]   Local Differential Privacy for Federated Learning [J].
Arachchige, Pathum Chamikara Mahawaga ;
Liu, Dongxi ;
Camtepe, Seyit ;
Nepal, Surya ;
Grobler, Marthie ;
Bertok, Peter ;
Khalil, Ibrahim .
COMPUTER SECURITY - ESORICS 2022, PT I, 2022, 13554 :195-216
[3]   Broadcast distributed voting algorithm in population protocols [J].
Bandealinaeini, Hamidreza ;
Salehkaleybar, Saber .
IET SIGNAL PROCESSING, 2020, 14 (10) :846-853
[4]   Secure Collaborative Deep Learning Against GAN Attacks in the Internet of Things [J].
Chen, Zhenzhu ;
Fu, Anmin ;
Zhang, Yinghui ;
Liu, Zhe ;
Zeng, Fanjian ;
Deng, Robert H. .
IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (07) :5839-5849
[5]  
Dai W, 2017, INT CONF ACOUST SPEE, P421, DOI 10.1109/ICASSP.2017.7952190
[6]  
du Terrail JO, 2022, ADV NEUR IN
[7]  
Duchi J, 2011, J MACH LEARN RES, V12, P2121
[8]  
Fan Mo, 2021, MobiSys '21: Proceedings of the 19th Annual International Conference on Mobile Systems, Applications, and Services, P94, DOI 10.1145/3458864.3466628
[9]   Comparison of the Utility of High-Resolution CT-DWI and T2WI-DWI Fusion Images for the Localization of Cholesteatoma [J].
Fan, X. ;
Ding, C. ;
Liu, Z. .
AMERICAN JOURNAL OF NEURORADIOLOGY, 2022, :1029-1035
[10]  
Fu C, 2022, PROCEEDINGS OF THE 31ST USENIX SECURITY SYMPOSIUM, P1397