Differentially Privacy-Preserving Federated Learning Using Wasserstein Generative Adversarial Network

Yichen Wan, Youyang Qu, Longxiang Gao, Yong Xiang · 2021 IEEE Symposium on Computers and Communications (ISCC) · 2021

Artificial intelligence (AI) requires a large amount of data to train high-quality machine learning (ML) models. However, due to privacy issues, individuals or organizations are not willing to share data with others, which results in “data islands”. This motivates the emergence of Federated Learning (FL), a novel ML framework allowing clients to exchange model parameters rather than the raw data. Unfortunately, the private data may be reconstructed by malicious participants by exploiting the context of model parameters in FL. This poses further challenges to privacy protection. To address this issue, we propose to integrate Wasserstein Generative Adversarial Network (WGAN) and differential privacy (DP) to protect the model parameters. WGAN is used to generate controllable random noise, which is then injected into model parameters. The new mechanism satisfies DP requirements while the data utility is highly improved. We experimentally demonstrate superior performances from aspects of convergence, accuracy, and data utility.

Read the paper · More papers on PaperTik