Differential Privacy for Noise-Sensitive Distributed Graph Federated Learning
Abstract
Federated graphs learning for graphs enables multiple clients to share model knowledge and engage in collaborative training while ensuring user data privacy. Nevertheless, federated learning for graphs also faces various security threats, such as privacy leakage and malicious attacks. On the other hand, compared with other security strategies, differential privacy offers low cost and high efficiency in protecting data in federated learning, yet it can compromise the training accuracy of federated learning for graphs and, in some cases, severely degrade training performance. Therefore, this paper considers noise-sensitive scenarios where even a small amount of noise can significantly impact training, and integrates knowledge distillation with distributed differential privacy federated learning for graphs. This approach enhances model training accuracy under noise-sensitive conditions while mitigating the adverse effects of differential privacy noise on training, all while ensuring model security. In addition to leveraging differential privacy to protect data and parameter privacy, we further aim to defend against malicious client attacks. By establishing a global consensus on the gradient clipping range, we use zero-knowledge proofs to provide sampled verification of the gradient range, demonstrating that the parameters uploaded by clients have been correctly clipped during training. Parameters that fail the verification are discarded, thereby further enhancing security.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.