Gradient Compression Framework for Adaptive Privacy Budget Allocation Based on Federated Learning

By adopting Top-k gradient dimensionality reduction and adaptive privacy budget allocation methods in federated learning, the balance between privacy, model practicality and communication efficiency is solved, the accuracy of the model and communication efficiency are improved, and the privacy budget consumption is reduced.

CN115496198BActive Publication Date: 2025-07-04GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210938530.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-05
Publication Date
2025-07-04
Estimated Expiration
2042-08-05

AI Technical Summary

Technical Problem

The existing federated learning framework is difficult to achieve a good balance between privacy, model practicality and communication efficiency, resulting in low model accuracy, high communication costs and excessive privacy budget consumption.

Method used

The top-k-based gradient dimensionality reduction compression module, the local differential privacy-based privacy protection module and the adaptive privacy budget allocation module are adopted to compress by selecting the Top-k dimension of the gradient parameters and allocating the privacy budget in different rounds to reduce the noise amount and communication cost.

Benefits of technology

While maintaining privacy protection, the accuracy and communication efficiency of the model are improved, the loss of privacy budget is reduced, and the overall performance of the model is optimized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115496198B_ABST
    Figure CN115496198B_ABST
Patent Text Reader

Abstract

The present invention discloses a gradient compression framework for adaptive privacy budget allocation based on federated learning, comprising: a gradient dimensionality reduction compression module based on Top-k, a privacy protection module based on local differential privacy, a parameter aggregation module for communication rounds, and an adaptive privacy budget allocation module; before uploading the gradient parameters trained by itself to the server, the client compresses the current gradient parameters through the gradient dimensionality reduction compression module based on Top-k, and then perturbs the gradient parameters through the privacy protection module based on local differential privacy, and then uploads the compressed and perturbed gradient parameters to the server, and the server aggregates the gradient parameters uploaded by the client; finally, the adaptive privacy budget allocation module allocates the privacy budget according to the required amount of noise in different rounds of training. The present invention reduces the communication cost, noise magnitude, and loss of the total privacy budget of the model, and the model has good accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of deep learning, and specifically includes a gradient compression framework based on adaptive privacy budget allocation for federated learning. Background Art

[0002] In the traditional centralized deep learning framework, users send their data containing sensitive information to a machine learning company (an untrusted third party). Once the data is sent to the third party, users cannot delete or control their own data, and these untrusted third parties may use their data for some illegal things, so their data may have the risk of privacy leakage. In 2015, Shokri et al. proposed a multi-party privacy-preserving collaborative deep learning model. In this model, each participant can independently train their model locally and then selectively share some model parameters of their local model with the central server. In this way, on the one hand, the sensitive data of the participants can be protected from leakage, and on the other hand, the shared parameters can be used to improve the accuracy of the models they train. Google first proposed the concept of federated learning based on Shokri's work, aiming to establish a high-quality distributed learning framework. In federated learning, data participants do not need to share raw data with each other, nor do they need to rely on a single trusted entity (central server) for distributed training of machine learning models. Konecny et al. proposed a federated learning model with good communication efficiency to solve the communication cost problem of federated learning. Considering that mobile device data in reality is distributed, McMahan et al. [8] proposed the federated averaging algorithm. Liu proposed a two-stage framework FedSel, which privately selects the Top-k dimensions for uploading and adding noise according to the contribution of gradient parameters in each iteration to alleviate the privacy and communication problems in federated learning based on local differential privacy. Zhao considered the unreliable participants in federated learning and proposed a new scheme called SecProbe, which allows participants to share model parameters and uses the exponential mechanism to handle unreliable participants.

[0003] For privacy protection in federated learning, there are many security models or privacy protection technologies that can provide reliable privacy guarantees. Such as secure multi-party computation (SMC), homomorphic encryption, differential privacy, etc. As a security protocol, secure multi-party computation is mainly used for secure aggregation, which can prevent malicious server attacks. For example, Danner et al. proposed a secure sum protocol using a tree topology. Another study based on secure multi-party computation is SecureML, where participants distribute their private data across two non-conflicting servers, and then the two servers use secure multi-party computation techniques to train a global model using the encrypted federated data of the participants. Bonawitz et al. proposed a secure multi-party aggregation method for FL, where participants need to encrypt their local updates, and the server then aggregates based on the encrypted parameters. Another privacy protection technology is homomorphic encryption, which is mainly used to encrypt the uploaded gradient parameters. However, this technology is not suitable for all clients because the server must rely on a non-colluding external participant to perform encryption or decryption. Both secure aggregation and homomorphic encryption methods involve a large amount of computational overhead, which is too expensive for the overall cost of the federated learning framework. In addition, Zhu et al. showed that using gradient compression and sparsification can help defend against privacy leakage from local updates. However, these methods require a high compression rate to achieve ideal defense performance, which will damage the accuracy of the model.

[0004] Considering the wide applicability of differential privacy in deep learning models, differential privacy can also be well used for privacy protection in federated learning. Differential privacy is an important data privacy protection technology in recent years. It is a method of adding artificial noise to prevent information leakage. Differential privacy can resist attacks from background knowledge, can adjust the degree of privacy protection according to the needs of privacy protection, and can also provide guarantees for the privacy protection of federated learning models. Abadi et al. proposed the DP-SGD algorithm, which adds noise to the gradients uploaded by clients to prevent external attackers from stealing model parameters and thus obtaining the original sensitive data of clients. Geyer et al. proposed a user-level differential privacy federated learning framework from the perspective of users, which provides different privacy protections for different users and makes a trade-off between privacy loss and model performance. Wei et al. proposed the NbAFL scheme, which appropriately adjusts its variance under a certain Gaussian noise perturbation level for the global data to meet the requirements of global DP.

[0005] Currently, the main research direction in this field is to achieve a balance among privacy, practicality, and communication efficiency in federated learning. How to achieve a better balance among these three aspects is the focus of this field. Therefore, our solution also seeks research points in this research direction and has studied relevant literature. Liu et al. proposed the FedSel solution. Considering that the number of uploaded parameters is proportional to the noise, this solution performs a Top-k screening on the parameters uploaded by the client and uses the gradient accumulation technique to stabilize the impact of the noise in the learning process. In addition, when selecting the Top-k dimensions for uploading, the authors also use the exponential mechanism of differential privacy to privately select k dimensions to ensure privacy when selecting dimensions. Before the client uploads the parameters to the server, first privately select the top k dimensions of the parameters with the largest gradient values instead of uploading all parameters. Then, add differential privacy noise to the selected k-dimensional parameters, and then upload the compressed noisy gradient vector to the server. The server aggregates the parameters uploaded by all participating clients and then proceeds to the next iteration. However, when this solution selects k-dimensional parameters for uploading, it uses different privacy protection mechanisms, resulting in a high computational cost for this solution and also damaging the accuracy of the model to a certain extent. Sun et al. proposed a novel design of local differential privacy mechanism for federated learning. This solution takes into account the differences in the parameter ranges of different deep learning model layers. It makes the update of local parameters differentially private by adapting to the different ranges of different layers of the deep neural network. In addition, this mechanism amplifies privacy through the aggregation mechanism of parameter shuffling, that is, under a smaller privacy budget and a higher privacy protection level, it can still ensure a very high model accuracy. Although this solution can achieve a good balance between privacy and model practicality, it ignores the aspect of communication efficiency. On the one hand, affected by the differential privacy mechanism, the convergence speed of the neural network will be relatively slow, which in turn leads to an increase in the number of iterations, thus increasing the communication cost. On the other hand, since the client uploads all its local parameters to the server, this inevitably reduces the communication efficiency.

[0006] The existing technologies of federated learning are difficult to achieve a good balance among privacy, model utility, and communication efficiency. On the one hand, when using relevant privacy protection technologies to protect the privacy of clients, since the gradient parameters of the neural network are added with noise, this inevitably has a negative impact on the effect of model training. In addition, since the model parameters are high-dimensional, their dimensions in the neural network often reach tens of thousands or even millions. However, the magnitude of the overall noise of the model is proportional to the dimension of the model parameters. Assuming that noise is added to each dimension of the model parameters, the noise volume of the model will increase exponentially, ultimately resulting in a relatively low model accuracy, that is, the model has poor utility. Therefore, adding noise to each dimension of the parameters will cause a series of problems such as excessive overall noise volume of the model and too low model accuracy. Regarding the communication cost of the model, since the speed of the uplink in the network is much slower than that of the downlink, if each dimension of the model parameters is uploaded, it will lead to a decrease in the communication efficiency of the model. In addition, since federated learning is based on distributed training with multiple users and multiple parameters, this means that in federated learning, the amount of parameters received by the server from a large number of clients is huge. If all users upload huge model parameters to the server, it will cause the problem of communication bottlenecks. Therefore, its communication problem is the most challenging problem in current research.

[0007] In addition, if noise is added to each parameter, it will cause the problem of excessive consumption of privacy budget. Therefore, the biggest problem faced by the current federated learning framework based on differential privacy is how to minimize the consumption of privacy budget while maintaining good model accuracy. Most current methods are based on unified and fixed privacy parameter settings, and due to the accumulation of a large amount of privacy loss in iterations, the model often performs poorly. The above analysis shows that one of the challenges of federated learning based on differential privacy is how to appropriately balance the privacy, accuracy, and communication efficiency of the model to ensure that the model still has good communication efficiency and model accuracy while protecting user privacy as much as possible. Summary of the Invention

[0008] In view of the existing problems, the purpose of the present invention is to provide a gradient compression framework for adaptive privacy budget allocation based on federated learning to solve the above problems.

[0009] The present invention provides the following technical solutions:

[0010] A gradient compression framework for adaptive privacy budget allocation based on federated learning, which includes: a gradient dimensionality reduction compression module based on Top-k, a privacy protection module based on local differential privacy, a parameter aggregation module for communication rounds, and an adaptive privacy budget allocation module; before the client uploads the gradient parameters obtained by its own training to the server, the current gradient parameters are compressed by the gradient dimensionality reduction compression module based on Top-k, and then, the gradient parameters are perturbed by the privacy protection module based on local differential privacy, and then the compressed and perturbed gradient parameters are uploaded to the server, and the server aggregates the gradient parameters uploaded by the client; in addition, the present invention allocates privacy budgets according to the required amount of noise in different rounds of training through the adaptive privacy budget allocation module.

[0011] After the client completes local iterative training, the gradient dimensionality reduction compression module based on Top-k calculates the local model gradient of the d-dimensional model parameters corresponding gradient is where t is the communication round.

[0012] The gradient dimensionality reduction compression module based on Top-k selects the top K dimensions with the largest absolute value of the gradient in the d dimensions of the model parameters and uploads them, where K < d; the local model gradient is sorted according to the absolute value size of each dimension: where the sorting algorithm sort sorts in descending order, represents the gradient after sorting, and the size of the gradient decreases sequentially according to the dimension; after sorting, the top K dimensions are selected from the sorted d-dimensional gradient parameters as the compressed model: where TopK represents the gradient compression scheme, represents the gradient after compression.

[0013] Preferably, the privacy protection module based on local differential privacy adds differential privacy noise to the gradient parameters uploaded by the client to achieve strict privacy protection. Specifically, for the gradient parameters G of the model, the perturbation algorithm randomizes each dimension of G and returns a perturbed gradient parameter G * ; the perturbation mechanism for each dimension of the gradient parameter g in G makes the following restrictions: g ∈ [c - r, c + r], where c is the center of the range of g and r is the radius of the range; the g is perturbed through the LDP mechanism:

[0014]

[0015] where, G *is the noise weight after being perturbed by the LDP mechanism, which contains d dimensions. is the differential privacy perturbation mechanism, and ε is the privacy budget allocated to a specific dimension in the gradient parameter.

[0016] Preferably, the privacy protection module based on local differential privacy perturbs the compressed gradient parameter using the LDP mechanism: where is the compressed and perturbed gradient.

[0017] Preferably, in the privacy protection module based on local differential privacy, according to the method of clipping the gradient parameter g, the range parameters c and r for restricting the gradient parameter g are set.

[0018] After all local clients add noise to the compressed gradient parameter, the parameter aggregation module of the communication round uploads its local gradient parameter to the server for aggregation. The server allocates the privacy budget ε t+1 to each client, and then sends the new global model to the participating clients for training. The above operations are repeated until the convergence condition is reached.

[0019] Preferably, after receiving the gradient parameter uploaded by the user, the parameter aggregation module of the communication round aggregates the gradient parameter through the following formula:

[0020]

[0021] where w t is the global model to be updated in the current round t, and w t+1 is the parameter of the global model updated in the next round t + 1. is the mean of all client gradient parameters, and α is the learning rate of the update algorithm.

[0022] Preferably, the adaptive privacy budget allocation module adopts the privacy budget allocation scheme:

[0023]

[0024] allocates different privacy budgets for different communication rounds, where ε is the total privacy budget for training, and ε t is the privacy budget allocated to the t-th round, and T is the total number of communication rounds.

[0025] The beneficial technical effects of the present invention are as follows:

[0026] The gradient compression framework provided by the present invention is based on an adaptive privacy budget allocation scheme for communication rounds to reduce the loss of privacy budget and the magnitude of model noise. First, different privacy budgets are allocated for different iteration rounds to maximize the trade-off between privacy and model performance. Second, to reduce the magnitude of the overall model noise, the present invention also uses a Top-K based gradient compression method. This scheme not only reduces the communication cost, noise magnitude, and loss of the total privacy budget of the model, but also provides better model accuracy under privacy protection. Description of the Drawings

[0027] Figure 1 It is a schematic diagram of the composition of the gradient compression framework for adaptive privacy budget allocation based on federated learning provided by the present invention;

[0028] Figure 2 It is a schematic flowchart of a preferred embodiment of the gradient compression framework for adaptive privacy budget allocation based on federated learning provided by the present invention. Detailed Embodiments

[0029] The embodiments of the present invention will be described in detail below. The following embodiments are implemented on the premise of the technical solution of the present invention, and detailed implementation manners and specific operation processes are given. However, the protection scope of the present invention is not limited to the following embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0030] Referring to "embodiments" herein means that specific features, structures, or characteristics described in connection with the embodiments can be included in at least one embodiment of the present application. The phrase appears in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that, without conflict, the embodiments described herein can be combined with other embodiments.

[0031] Embodiment

[0032] As Figure 1As shown in the figure, the gradient compression framework for adaptive privacy budget allocation based on federated learning provided by the embodiments of the present invention includes: a gradient dimensionality reduction compression module based on Top-k, a privacy protection module based on local differential privacy, a parameter aggregation module for communication rounds, and an adaptive privacy budget allocation module; before the client uploads the gradient parameters obtained by its own training to the server, the current gradient parameters are compressed by the gradient dimensionality reduction compression module based on Top-k, and then, the gradient parameters are perturbed by the privacy protection module based on local differential privacy, and then the compressed and perturbed gradient parameters are uploaded to the server, and the server aggregates the gradient parameters uploaded by the client; finally, the adaptive privacy budget allocation module allocates the privacy budget according to the required amount of noise in different rounds of training.

[0033] As Figure 2 shown, after the gradient dimensionality reduction compression module based on Top-k completes local iterative training at the client, it calculates the gradient of the local model of the d-dimensional model parameters as where t is the communication round.

[0034] The gradient dimensionality reduction compression module based on Top-k selects the top K dimensions with the largest absolute values of the gradients in the d dimensions of the model parameters and uploads them, where K < d; sorts the local model gradients according to the absolute value size of each dimension: where the sorting algorithm sort sorts in descending order, represents the sorted gradients, and the magnitudes of the gradients decrease sequentially according to the dimensions; after sorting, the top K dimensions are selected from the sorted d-dimensional gradient parameters as the compressed model: where TopK represents the gradient compression scheme, represents the compressed gradient.

[0035] The privacy protection module based on local differential privacy realizes strict privacy protection by adding differential privacy noise to the gradient parameters uploaded by the client. Specifically, for the gradient parameters G of the model, the perturbation algorithm randomizes each dimension of G and returns a perturbed gradient parameter G * ; the perturbation mechanism imposes the following restrictions on the gradient parameter g of each dimension in G: g ∈ [c - r, c + r], where c is the center of the range of g and r is the radius of the range; perturbs g through the LDP mechanism:

[0036]

[0037] where, G *is the noise weight after being perturbed by the LDP mechanism, which contains d dimensions. is the differential privacy perturbation mechanism, and ε is the privacy budget allocated to a specific dimension in the gradient parameter.

[0038] The privacy protection module based on local differential privacy compresses the gradient parameter and perturbs it using the LDP mechanism: where is the compressed and perturbed gradient.

[0039] In the privacy protection module based on local differential privacy, according to the method of clipping the gradient parameter g, the range parameters c and r for restricting the gradient parameter g are set.

[0040] After all local clients add noise to the compressed gradient parameter, the parameter aggregation module in the communication round uploads its local gradient parameter to the server for aggregation. The server allocates the privacy budget ε for the current communication round t + 1 t+1 to each client, and then sends the new global model to the participating clients for training. The above operations are repeated until the convergence condition is reached.

[0041] After receiving the gradient parameter uploaded by the user, the parameter aggregation module in the communication round aggregates the gradient parameter through the following formula:

[0042]

[0043] where w t is the global model to be updated in the current round t, and w t+1 is the parameter of the global model updated in the next round t + 1. is the mean of all client gradient parameters, and α is the learning rate of the update algorithm.

[0044] The adaptive privacy budget allocation module adopts the privacy budget allocation scheme:

[0045]

[0046] allocates different privacy budgets for different communication rounds. Among them, ε is the total privacy budget for training, and ε t is the privacy budget allocated to the t-th round, and T is the total number of communication rounds.

[0047] The gradient compression framework provided in the above embodiments of the present invention is based on an adaptive privacy budget allocation scheme for communication rounds to reduce the loss of privacy budget and the magnitude of model noise. First, different privacy budgets are allocated for different iteration rounds to maximize the trade-off between privacy and model performance. Second, in order to reduce the magnitude of the overall model noise, this paper also uses a Top-K based gradient compression method. This scheme not only reduces the communication cost, noise magnitude, and loss of the total privacy budget of the model, but also provides better model accuracy under privacy protection.

[0048] The preferred specific embodiments of the present invention have been described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations according to the concept of the present invention without creative efforts. Therefore, all technical solutions that can be obtained by those skilled in the art in the technical field based on the concept of the present invention through logical analysis, reasoning, or limited experiments on the basis of the prior art should fall within the protection scope determined by the claims.

Claims

1. A gradient compression framework for adaptive privacy budget allocation based on federated learning, characterized in that Including: A Top-k based gradient dimensionality reduction compression module, a local differential privacy based privacy protection module, a communication round parameter aggregation module, and an adaptive privacy budget allocation module; before the client uploads the gradient parameters obtained by its own training to the server, the current gradient parameters are compressed by the Top-k based gradient dimensionality reduction compression module, and then, the gradient parameters are perturbed by the local differential privacy based privacy protection module, and then the compressed and perturbed gradient parameters are uploaded to the server, and the server aggregates the gradient parameters uploaded by the client; finally, the adaptive privacy budget allocation module allocates privacy budgets according to the required amount of noise in different rounds of training; After the Top-k based gradient dimensionality reduction compression module completes local iterative training on the client side, it calculates the local model gradient d-dimensional model parameters The corresponding gradient of is where t is the communication round; The Top-k based gradient dimensionality reduction compression module selects the top K dimensions with the largest absolute values of gradients in the d dimensions of the model parameters for uploading, where K < d; the local model gradients are sorted according to the absolute value size of each dimension as follows: Among them, the sorting algorithm sort sorts in descending order, denotes the gradients after sorting, and the magnitudes of the gradients decrease successively according to the dimensions; after sorting, the top K dimensions are selected from the sorted d-dimensional gradient parameters as the compressed model: Among them, TopK represents the gradient compression scheme, denotes the gradients after compression.

2. The gradient compression framework for adaptive privacy budget allocation based on federated learning according to claim 1, wherein The privacy protection module based on local differential privacy achieves strict privacy protection by adding differential privacy noise to the gradient parameters uploaded by the client. Specifically, for the gradient parameter G of the model, the perturbation algorithm randomizes each dimension of G and returns a perturbed gradient parameter G * ; Perturbation mechanism For the gradient parameter g of each dimension in G, the following restrictions are imposed: g ∈ [c - r, c + r], where c is the center of the range of g and r is the radius of the range; g is perturbed through the LDP mechanism: Among them, G * is the noise weight after being perturbed by the LDP mechanism, which contains d dimensions, is the differential privacy perturbation mechanism, and ε is the privacy budget allocated to a specific dimension in the gradient parameter.

3. The gradient compression framework for adaptive privacy budget allocation based on federated learning according to claim 2, characterized in that, The privacy protection module based on local differential privacy perturbs the compressed gradient parameters using the LDP mechanism: wherein, is the compressed and perturbed gradient.

4. The gradient compression framework for adaptive privacy budget allocation based on federated learning according to claim 3, wherein In the local differential privacy based privacy protection module, according to the method of pruning the gradient parameter g, the range parameters c and r for restricting the gradient parameter g are set.

5. The gradient compression framework for adaptive privacy budget allocation based on federated learning according to claim 2, characterized in that, After all local clients add noise to the compressed gradient parameters, the parameter aggregation module of the communication round uploads its local gradient parameters to the server for aggregation. The server allocates a privacy budget ε t+1 to each client, and then sends the new global model to the clients participating in the training for training. The above operations are looped until the convergence condition is reached.

6. The gradient compression framework for adaptive privacy budget allocation based on federated learning according to claim 1, wherein The adaptive privacy budget allocation module adopts a privacy budget allocation scheme: Allocate different privacy budgets for different communication rounds, where ε is the total privacy budget for training, and ε t is the privacy budget allocated to the t-th round, and T is the total number of communication rounds.

Citation Information

Patent Citations

  • Efficient frequent pattern mining method for differential privacy protection

    CN110096900A

  • Federated learning method and device based on differential privacy and storage medium

    CN111091199A