Topology-Aware Differential Privacy for Decentralized Image Classification

被引:13
作者
Guo, Shangwei [1 ]
Zhang, Tianwei [2 ]
Xu, Guowen [2 ]
Yu, Han [2 ]
Xiang, Tao [1 ]
Liu, Yang [2 ]
机构
[1] Chongqing Univ, Coll Comp Sci, Chongqing 400044, Peoples R China
[2] Nanyang Technol Univ NTU, Sch Comp Sci & Engn, Singapore 639798, Singapore
基金
新加坡国家研究基金会; 中国国家自然科学基金;
关键词
Training; Privacy; Usability; Differential privacy; Network topology; Learning systems; Topology; Decentralized learning; image processing; differential privacy; topology;
D O I
10.1109/TCSVT.2021.3105723
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Image classification is a fundamental artificial intelligence task that labels images into one of some predefined classes. However, training complex image classification models requires a large amount of computation resources and data in order to reach state-of-the-art performance. This demand drives the growth of distributed deep learning, where multiple agents cooperatively train global models with their individual datasets. Among such learning systems, decentralized learning is particularly attractive, as it can improve the efficiency and fault tolerance by eliminating the centralized parameter server, which could be the single point of failure or performance bottleneck. Although the agents do not need to disclose their training image samples, they exchange parameters with each other at each iteration, which can put them at the risk of data privacy leakage. Past works demonstrated the possibility of recovering training images from the exchanged parameters. One common defense direction is to adopt Differential Privacy (DP) to secure the optimization algorithms such as Stochastic Gradient Descent (SGD). Those DP-based methods mainly focus on standalone systems, or centralized distributed learning. How to enforce and optimize DP protection in decentralized learning systems is unknown and challenging, due to their complex communication topologies and distinct learning characteristics. In this paper, we design TOP- DP, a novel solution to optimize the differential privacy protection of decentralized image classification systems. The key insight of our solution is to leverage the unique features of decentralized communication topologies to reduce the noise scale and improve the model usability. (1) We enhance the DP-SGD algorithm with this topology-aware noise reduction strategy, and integrate the time-aware noise decay technique. (2) We design two novel learning protocols (synchronous and asynchronous) to protect systems with different network connectivities and topologies. We formally analyze and prove the DP requirement of our proposed solutions. Experimental evaluations demonstrate that our solution achieves a better trade-off between usability and privacy than prior works. To the best of our knowledge, this is the first DP optimization work from the perspective of network topologies.
引用
收藏
页码:4016 / 4027
页数:12
相关论文
共 50 条
[41]   Triangle Matters! TopDyG: Topology-aware Transformer for Link Prediction on Dynamic Graphs [J].
Zhang, Xin ;
Cai, Fei ;
Zheng, Jianming ;
Pan, Zhiqiang ;
Chen, Wanyu ;
Chen, Honghui ;
Chen, Chonghao .
PROCEEDINGS OF THE ACM WEB CONFERENCE 2025, WWW 2025, 2025, :3607-3617
[42]   Topology-Aware Keypoint Detection via Skeleton-Based Shape Matching [J].
Li, Yushi ;
Li, Pengfei ;
Xu, Meng ;
Wang, Yunzhe ;
Ji, Chengtao ;
Han, Yu ;
Chen, Rong .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2025, 71 (01) :367-378
[43]   Auditable Homomorphic-Based Decentralized Collaborative AI With Attribute-Based Differential Privacy [J].
Yeh, Lo-Yao ;
Tseng, Sheng-Po ;
Lu, Chia-Hsun ;
Shen, Chih-Ya .
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2025, 22 (02) :989-1004
[44]   A Differential Privacy Topology Scheme for Average Path Length Query [J].
Dong, Tong ;
Zeng, Yong ;
Liu, Zhi-Hong ;
Ma, Jian-Feng ;
Zhu, Xiao-Yan .
JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2021, 37 (04) :885-899
[45]   A Network Topology-aware Selectively Distributed Firewall Control in SDN [J].
Thuy Vinh Tran ;
Ahn, Heejune .
2015 INTERNATIONAL CONFERENCE ON ICT CONVERGENCE (ICTC), 2015, :89-94
[46]   Topology-aware Federated Learning in Edge Computing: A Comprehensive Survey [J].
Wu, Jiajun ;
Dong, Fan ;
Leung, Henry ;
Zhu, Zhuangdi ;
Zhou, Jiayu ;
Drew, Steve .
ACM COMPUTING SURVEYS, 2024, 56 (10)
[47]   Topology-Aware Neural Model for Highly Accurate QoS Prediction [J].
Li, Jiahui ;
Wu, Hao ;
Chen, Jiapei ;
He, Qiang ;
Hsu, Ching-Hsien .
IEEE TRANSACTIONS ON PARALLEL AND DISTRIBUTED SYSTEMS, 2022, 33 (07) :1538-1552
[48]   Image Pixelization with Differential Privacy [J].
Fan, Liyue .
DATA AND APPLICATIONS SECURITY AND PRIVACY XXXII, DBSEC 2018, 2018, 10980 :148-162
[49]   Towards a Realistic Decentralized Naive Bayes with Differential Privacy [J].
Giaretta, Lodovico ;
Marchioro, Thomas ;
Markatos, Evangelos ;
Girdzijauskas, Sarunas .
E-BUSINESS AND TELECOMMUNICATIONS, ICSBT 2022, SECRYPT 2022, 2023, 1849 :98-121
[50]   Research on an Ensemble Classification Algorithm Based on Differential Privacy [J].
Jia, Junjie ;
Qiu, Wanyong .
IEEE ACCESS, 2020, 8 :93499-93513