Privacy-Preserving Federated Learning via Rerandomizable Garbled Circuits
Abstract
With the rapid development of the Internet of Things (IoT), the security and privacy of personal data has received widespread attention. Federated learning models protect personal privacy data through distributed collaborative training models, but it has been shown that personal privacy data can be inferred from uploaded parameters. Federated learning models also face the challenges of privacy leakage risk, computational inefficiency and lack of verifiability. Existing differential privacybased federated learning models and homomorphic encryptionbased federated learning models are unable to balance model accuracy and security. They also face the problem of inefficient computation of client-side local data and high communication overhead. Therefore, in this paper, we propose a federated learning framework (RGC-FL) based on Re-randomizable Garbled Circuits (RGC), which achieves a balance between privacy protection and computational efficiency through dynamic encryption and re-randomization techniques. The model updates are first encrypted at the client using the obfuscated circuits and then uploaded to the server, and then the ciphertext updates are aggregated by the re-randomization technique to avoid the leakage of the original data. Secondly, the client verifies the correctness of the server’s aggregation results by zero-knowledge proof. Finally based on DDH assumption and Kilian randomization technique to defend against hybrid attacks in dynamic input scenarios. We experimentally show that the model accuracy of RGC-FL on MNIST and CIFAR-10 datasets is 97.3% and 83.9%, respectively, which is close to plaintext federated learning and significantly outperforms the Differential Privacy (DP-FL) and Fully Homomorphic Encryption scheme (FHE-FL). In terms of efficiency, the training time for a single round is only 32% of that of FHE-FL (12.4 sec vs. 38.7 sec), and the communication overhead is reduced by $80 \%(5.2 \mathrm{MB}$ vs. 25.6 MB). This paper provides an efficient and secure solution for federated learning in highly privacy-sensitive domains and promotes the wide application of AI under compliance requirements.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.