Lightweight Privacy Protection Against Channel-Level Gradient Leakage Attack in Federated Learning
Zhe Li, Honglong Chen, Yudong Gao, Huansheng Xue · 2024
Federated learning is a distributed machine learning framework that enhances privacy and data security. However, model parameters communicated between server and clients are vulnerable to gradient leakage attacks (GLAs), posing a significant privacy risk. While differential privacy offers strong protection, it often comes at the cost of considerable performance degradation. To address this challenge, we explore a channel-level gradient leakage attack for the first time, discovering that successful attacks can be conducted using only partial channel information from certain parameters. Based on this insight, we leverage the empirical Fisher information matrix to estimate the information contained in each channel and propose a lightweight channel-level privacy protection method (FedLCP) to defend against GLAs and our newly explored channel-level gradient leakage attack. Extensive experiments on three datasets demonstrate that FedLCP provides privacy protection comparable to differential privacy, with up to a 37.78% improvement in accuracy and excellent convergence.