Leveraging the Physical Layer for Differential Privacy in Over-the-Air Federated Learning

Jiayu Mao, Tongxin Yin, Aylin Yener, Mingyan Liu · 2024

Federated learning (FL) is a distributed learning framework that by design allows local edge devices to keep their training data. However, privacy leakage occurs through model updates and is a privacy protection concern that needs to be addressed. Over-the-air FL (OTA-FL) is a variant of FL designed for wireless edge networks by utilizing the inherent superposition property of the wireless medium. The wireless physical layer (PHY), in addition to providing resource and communication-efficient collaborative training via OTA-FL, can also be leveraged to enhance privacy for FL. This paper presents the PHY design to ensure differentially private (DP) OTA-FL. Specifically, by leveraging the Gaussian noise naturally present in the wireless channel, and deploying a dedicated artificial noise generator (cooperative jammer) when needed, a fully decentralized, dynamic power control strategy is proposed. This design relies on a resource-efficient FL framework with first-order approximation applied at every even iteration, thereby reducing the amount of information needed from clients. This approach can eliminate the need for artificial noise injection at the client side, typically required to achieve DP; the cooperative jammer is used for higher privacy requirement without transmission efficiency loss. The privacy analysis is provided via the Moments Accountant method, providing a tight privacy assessment. The convergence analysis is provided for non-convex learning objectives. Experiments conducted on real-world non-i.i.d. data demonstrate that our scheme outperforms the state-of-the-art method under the same DP requirement and illustrate the effectiveness of cooperative jammer in the case of stringent privacy requirements.

Read the paper · More papers on PaperTik