AIセキュリティポータル K Program
The Effect of Quantization in Federated Learning: A Rényi Differential Privacy Perspective
Share
Abstract
Federated Learning (FL) is an emerging paradigm that holds great promise for privacy-preserving machine learning using distributed data. To enhance privacy, FL can be combined with Differential Privacy (DP), which involves adding Gaussian noise to the model weights. However, FL faces a significant challenge in terms of large communication overhead when transmitting these model weights. To address this issue, quantization is commonly employed. Nevertheless, the presence of quantized Gaussian noise introduces complexities in understanding privacy protection. This research paper investigates the impact of quantization on privacy in FL systems. We examine the privacy guarantees of quantized Gaussian mechanisms using R\'enyi Differential Privacy (RDP). By deriving the privacy budget of quantized Gaussian mechanisms, we demonstrate that lower quantization bit levels provide improved privacy protection. To validate our theoretical findings, we employ Membership Inference Attacks (MIA), which gauge the accuracy of privacy leakage. The numerical results align with our theoretical analysis, confirming that quantization can indeed enhance privacy protection. This study not only enhances our understanding of the correlation between privacy and communication in FL but also underscores the advantages of quantization in preserving privacy.
Communication-Efficient Learning of Deep Networks from Decentralized Data
H. Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, Blaise Agüera y Arcas
Published: 2.18.2016
Decentralized federated learning with unreliable communications
H. Ye, L. Liang, G. Y. Li
Published: 2022
Gradvit: Gradient inversion of vision transformers
Ali Hatamizadeh, Hongxu Yin, Holger R Roth, Wenqi Li, Jan Kautz, Daguang Xu, Pavlo Molchanov
Published: 2022
Enhanced Membership Inference Attacks against Machine Learning Models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, Reza Shokri
Published: 11.18.2021
Differentially private federated learning on heterogeneous data
M. Noble, A. Bellet, A. Dieuleveut
Published: 2022
Fedpaq: A communication-efficient federated learning method with periodic averaging and quantization
A. Reisizadeh, A. Mokhtari, H. Hassani, A. Jadbabaie, R. Pedarsani
Published: 2020
Hierarchical federated learning with quantization: Convergence analysis and system design
L. Liu, J. Zhang, S. Song, K. B. Letaief
Published: 2023
cpsgd: Communication-efficient and differentially-private distributed SGD
Naman Agarwal, Ananda Theertha Suresh, Felix X. Yu, Sanjiv Kumar, Brendan McMahan
Published: 2018
The discrete Gaussian for differential privacy
C. Canonne, G. Kamath, T. Steinke
Published: 2020
Binary federated learning with client-level differential privacy
L. Liu, J. Zhang, S. Song, K. B. Letaief
Published: 2023
Effects of quantization on federated learning with local differential privacy
M. Kim, O. Gunl ü, R. F. Schaefer
Published: 2022
D2p-fed: Differentially private federated learning with efficient communication
L. Wang, R. Jia, D. Song
Published: 2021
Distributed mean estimation with limited communication
A. T. Suresh, F. X. Yu, S. Kumar, H. B. McMahan
Published: 2017
Renyi differential privacy
I. Mironov
Published: 2017
Enhanced Membership Inference Attacks against Machine Learning Models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, Reza Shokri
Published: 11.18.2021
Membership inference attacks from first principles
N. Carlini, S. Chien, M. Nasr, S. Song, A. Terzis, F. Tramer
Published: 2022
Share