Balancing Centralized and Local Differential Privacy in Pneumonia Diagnosis
Bingbing Zhang, Xin Zhang, Liwei Luo, Heyuan Huang, Chi Zhang · 2024
As a collaborative learning method, federated learning trains models on large datasets without sharing raw data. However, sharing gradients generated with the aggregation server could reveal sensitive information related to the raw data in federated learning. Privacy-preserving methods such as differential privacy (DP) are needed for federated learning clinical applications. Existing centralized DP relies on a trusted server, while local DP suffers from the accuracy limitations of adding noise from each data owner. In this paper, we propose a privacy-preserving federated learning method by centralized differential privacy without a trusted server. By encrypting each local gradient with multikey homomorphic encryption, we can prevent the aggregation server from inferring local data privacy during the training process. By adding noise to the aggregated gradient with centralized DP, we prevent medical institutions from inferring private information about other institutions from the aggregated global update. The utilization of multikey homo-morphic encryption eliminates the need for a trusted server. Our experimental evaluation on chest X-ray dataset demonstrates that our proposed approach has a 9% loss in accuracy compared to non-private federated learning.