A Perturbation-Based Privacy Leakage Defense Method for Federal Learning
Changsong Yang, Sirui Huang, Yong Ding, Hai Liang, Siyuan Jia, Xinyong Peng · 2024
Federated Learning(FL) is an emerging distributed learning algorithm where each participant trains a model locally and uploads the parameters to a central server. However, recent studies have indicated that sharing model information can lead to data leakage. Attackers could potentially steal private training data from other participants’ shared gradients through Deep Leakage from Gradients(DLG) attacks. In this paper, we propose a perturbation-based privacy defense method in FL to counteract DLG attacks. The core idea of our defense strategy is to perturb the shared gradients, thereby disrupting the attacker’s ability to reconstruct the training data, making it impossible for attackers to rebuild the training data. To assess the effectiveness of our defense strategy, we conducted experiments against DLG attacks on the MNIST and CIFAR100 datasets. The experimental results indicate that our proposed defense strategy can counteract DLG attacks with only a minor sacrifice in accuracy. Compared to two existing baseline defense methods, our approach achieves better defense outcomes while more effectively preserving the performance of the original model.