FedMONN: Meta Operation Neural Network for Secure Federated Aggregation
Dan Meng, Hongyu Li, Fan Zhu, Xiaolin Li · 2020
Federated learning enables collaborative machine learning among multiple independent participants while preserving data privacy of each participant through model aggregation during training. However, model aggregation still faces potential risks that are associated with indirect leakage, such as parameters. In this paper, we first propose an algorithm called Meta Operation Neural Network (MONN) to perform basic arithmetic operations on encrypted data and generate operation results in a plaintext way. MONN is actually a general neural network composed of an encoder and a meta operation decoder, where both the encryption and meta decryption are lossless. MONN can be applied to federated learning for secure model aggregation. In this way, data privacy can be well preserved not only from malicious attackers but also untrustworthy servers. Experimental results reveal the following three key properties: 1) The proposed MONN based federated aggregation method (denoted as FedMONN) can reach satisfactory performance comparable with non-federated counterparts; 2) FedMONN is more secure than the classic federated averaging and one-time pad aggregation, even the server is not a trustable third party; 3) FedMONN is much efficient than the federated aggregation based on the Paillier homomorphic encryption technique.