Evaluation of Membership Inference Attack Against Federated Learning With Differential Privacy on Edge Devices

Rei Ueda, Tsunato Nakai, Kota Yoshida, Takeshi Fujino · 2023

Federated learning (FL) is a distributed deep learning technique in which training parties are split into a server and clients. Each client trains a model with its own training data and only sends the model to the server. Here, the clients do not share training data with each other, including private information. While this may be beneficial for data privacy, there is the growing threat of membership inference attacks (MIAs), which reveal private information in the training data from the model. FL with differential privacy (DP) is one of the countermeasures against MIAs. In this paper, we evaluated the relationship between the robustness against an MIA and the amount of noise added by DP in FL with varying calculation precisions, i.e., IEEE754 32-bit floating-point, IEEE754 16-bit (half-precision) floating-point, and bfloat16. The latter two conditions were implemented assuming that the training process of the client is performed on edge devices with limited computational resources. Our experimental results showed that there was a trade-off between defense and model accuracy. Furthermore, we found that the half-precision floating-point calculations do not cause significant degradation in the model accuracy even when used with DP.

Read the paper · More papers on PaperTik