Federated Learning Privacy Control Under Device Dropout
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Federated learning systems face the risk of personal information leakage due to disconnection of electronic devices during data transmission, as existing methods do not adequately protect user privacy when devices drop out of the network.
Innovation Solution
A method and system for refining AI models using differential privacy protection and modification techniques, involving the transmission of first and second differential privacy data, along with noise level adjustments and secure key sharing among devices, to ensure secure data exchange and model refinement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If federated learning is implemented to protect user privacy by keeping data local, then personal information security is improved, but the system becomes vulnerable to privacy leakage when devices disconnect during transmission
Solution Approach 1:
The patent applies preliminary anti-action by adding differential privacy noise to model parameters before transmission. This preventive measure is taken in advance to counteract potential privacy leakage risks that could occur during device disconnection or data transmission, ensuring that even if parameters are intercepted, the underlying user data remains protected.
Solution Approach 2:
The system performs preliminary action by pre-processing model parameters with differential privacy protection before transmission occurs. The noise addition and privacy preservation steps are completed in advance, so that when devices disconnect or data is transmitted, the privacy protection is already in place and cannot be compromised by transmission failures.
2Reliability
If differential privacy protection data is transmitted to protect privacy, then privacy security is improved, but the data transmission complexity increases
Solution Approach 1:
The patent uses an intermediary approach by introducing a differential privacy mechanism as a mediator between the original model parameters and the transmitted data. This intermediary layer adds controlled noise and transforms the data in a way that protects privacy while maintaining the essential learning signal, thereby balancing privacy protection with transmission efficiency.
3Reliability
If noise level is adjusted based on identification information to enhance privacy, then privacy protection is improved, but the processing time and system complexity increase
Solution Approach 1:
The system applies dynamics by making the noise level adjustable and adaptive based on identification information. The differential privacy parameters are not fixed but can be dynamically modified according to device identity, allowing the system to optimize between privacy protection strength and processing efficiency differentially for each device without requiring maximum processing for all devices.
Data Source
AI summary
Embodiments of the disclosure relate to an electronic device and a server for federated learning, and a method of the same. A method of refining a core artificial intelligence (AI) model built in the server includes transmitting, to each of a plurality of electronic devices performing federated learning with the core AI model, data for requesting transmission of first data used for refining the core AI model, receiving first data from at least one of the plurality of electronic devices, identifying an electronic device that has transmitted the first data from among the plurality of electronic devices, transmitting data for requesting transmission of second data to the electronic device that has transmitted the first data among the plurality of electronic devices, receiving second data from the electronic device that has transmitted the first data, and refining the core AI model by using the first data and the second data, wherein the first data includes first differential privacy protection data for protecting private data of each of the plurality of electronic devices, and the second data includes differential privacy modification data used to modify the first differential privacy protection data into second differential privacy protection data.


