Computer Engineering & Science ›› 2024, Vol. 46 ›› Issue (09): 1606-1615.
• Computer Network and Znformation Security • Previous Articles Next Articles
XIAO Di,YU Zhu-yang,LI Min,WANG Lian
Received:
Revised:
Accepted:
Online:
Published:
Abstract: Model security and clients privacy are urgent challenges to be addressed in federated learning. In order to simultaneously tackle these challenges, a federated learning scheme based on differential privacy and model clustering is proposed. Local differential privacy is introduced in clients updates to protect clients privacy by disrupting the parameters. To ensure precise clustering of noisy model updates, cosine gradient is defined for the first time to cluster noisy model updates. Based on the clustering results, malicious models are accurately identified and filtered. Finally, global differential privacy is introduced to resist potential backdoor attacks. The noise boundary of global noise is obtained by theoretical analysis and it is proved that the total noise introduced by our scheme is lower than that introduced by the classical model security scheme. The experimental results demonstrate that our scheme can achieve the expected goals in terms of accuracy, robustness and privacy.
Key words: federated learning, model security, backdoor attack, differential privacy, privacy protection
XIAO Di, YU Zhu-yang, LI Min, WANG Lian. A secure federated learning scheme based on differential privacy and model clustering[J]. Computer Engineering & Science, 2024, 46(09): 1606-1615.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://joces.nudt.edu.cn/EN/
http://joces.nudt.edu.cn/EN/Y2024/V46/I09/1606