Gradient Noise Constraint for Secure Joint Training
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In joint training models for machine learning, there is a risk of data leakage from active participants to passive participants during gradient transfer, compromising data security while affecting the efficiency and accuracy of the training process.
Innovation Solution
The method involves acquiring gradient correlation information for reference samples, determining a constraint condition for data noise based on positive and negative examples, correcting initial gradient transfer values to ensure consistency across different sample labels, and sending the corrected gradient transfer information to passive participants, thereby protecting data security and maintaining training efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If gradient transfer information is sent from active participant to passive participant for joint training, then training effectiveness is improved, but data security deteriorates due to potential data leakage
Solution Approach 1:
The patent introduces noise as an intermediary element that is added to the gradient transfer information. This noise acts as a mediator that obscures the direct relationship between the original data and the gradient information, allowing the passive participant to receive training signals without being able to infer sensitive information about the active participant's data. The noise serves as a protective layer that enables information flow while preventing data leakage.
Solution Approach 2:
The patent modifies the parameters of the gradient transfer information by adding controlled noise with specific statistical properties. The noise is designed with particular variance and distribution characteristics that allow it to mask sensitive information while preserving the essential training signal. By changing the parameters of the gradient information through noise addition, the system achieves both training effectiveness and data protection.
2Reliability
If noise is added to gradient transfer information to protect data security, then data leakage is prevented, but training efficiency deteriorates due to noise interference
Solution Approach 1:
The patent carefully controls the parameters of the added noise, specifically its variance and distribution, to optimize the balance between protection and efficiency. The noise parameters are tuned so that they provide sufficient masking for data security while minimizing the distortion of the training signal. This parameter optimization ensures that the noise provides protection without excessively degrading training efficiency.
Solution Approach 2:
The system employs feedback mechanisms to monitor the impact of noise on training convergence and performance. By observing how the noise affects the training process, the system can adjust noise parameters or apply correction techniques to maintain training efficiency. The feedback loop allows the system to adapt the noise characteristics to achieve both security and efficiency goals.
3Reliability
If noise is added to gradient transfer information, then data security is improved, but convergence stability deteriorates due to noise-induced fluctuations
Solution Approach 1:
The patent controls the parameters of the added noise, particularly its variance and distribution characteristics, to ensure that the noise provides security protection without causing excessive fluctuations that would destabilize convergence. The noise parameters are carefully selected to balance the masking effect with the stability requirement, preventing divergence while maintaining data protection.
Solution Approach 2:
The system applies noise with predetermined characteristics that are designed to cushion against potential convergence issues. By selecting noise parameters in advance that are known to maintain stability, the system prevents convergence problems before they occur. The pre-designed noise characteristics act as a cushion that protects both data security and convergence stability.
Data Source
AI summary
The present disclosure relates to a data protection method, an apparatus, a medium and a device. The method includes: acquiring gradient association information respectively corresponding to reference samples of a target batch of an active party of a joint training model; according to the proportion occupied respectively by reference samples of positive examples and reference samples of negative examples in all reference samples of the target batch, determining a constraint condition of the data noise to be added; determining information of said data noise according to the gradient association information and the constraint condition corresponding to the reference samples; correcting, according to the information of said data noise, an initial gradient transmission value corresponding to each reference sample, so as to obtain target gradient transmission information; and sending the target gradient transmission information to a passive party of the joint training model.

