We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Protecting Data from all Parties: Combining FHE and DP in Federated Learning

Abstract: This paper tackles the problem of ensuring training data privacy in a federated learning context. Relying on Homomorphic Encryption (HE) and Differential Privacy (DP), we propose a framework addressing threats on the privacy of the training data. Notably, the proposed framework ensures the privacy of the training data from all actors of the learning process, namely the data owners and the aggregating server. More precisely, while HE blinds a semi-honest server during the learning protocol, DP protects the data from semi-honest clients participating in the training process as well as end-users with black-box or white-box access to the trained model. In order to achieve this, we provide new theoretical and practical results to allow these techniques to be rigorously combined. In particular, by means of a novel stochastic quantisation operator, we prove DP guarantees in a context where the noise is quantised and bounded due to the use of HE. The paper is concluded by experiments which show the practicality of the entire framework in terms of both model quality (impacted by DP) and computational overhead (impacted by HE).
Comments: 21 pages, 2 figures, 2 tables
Subjects: Cryptography and Security (cs.CR); Machine Learning (cs.LG)
ACM classes: I.2.6; E.3
Cite as: arXiv:2205.04330 [cs.CR]
  (or arXiv:2205.04330v2 [cs.CR] for this version)

Submission history

From: Arnaud Grivet Sébert [view email]
[v1] Mon, 9 May 2022 14:33:44 GMT (51kb,D)
[v2] Tue, 31 May 2022 12:56:21 GMT (177kb,D)

Link back to: arXiv, form interface, contact.