Search papers, labs, and topics across Lattice.
This paper introduces MaxModShift, a novel approach to enhancing model privacy in federated learning by designing model shifts that maximize the disparity between the model learned by an eavesdropper and the central server. By driving the Fisher Information Matrix for the eavesdropper's estimation problem to singularity, the method ensures that the eavesdropper cannot effectively learn the model. The results show that MaxModShift outperforms previous designs while requiring less transmission power and bandwidth, making it a more efficient solution for maintaining privacy in federated settings.
Eavesdroppers can be effectively thwarted in federated learning environments with a new model shift design that reduces power consumption and bandwidth needs.
Model learning by an eavesdropper is treated as an estimation problem in a federated environment. The Fisher Information Matrix for the eavesdropper's estimation problem is driven to singularity through a signaling design; this ensures that the eavesdropper cannot learn the model. Herein, the innovation of prior designs is that model shifts are designed to maximize the difference in the model learned by Eve and the central server while satisfying a transmission power constraint for the agents. Two shift schemes are provided. MaxModShift outperforms a prior ModShift design while requiring lesser transmission power. Compared to a noise injection scheme, MaxModShift performs better while requiring a lower bandwidth secret channel and a reduced average power consumption.