Differentially Private Federated Learning (DP-FL) has garnered attention as a collaborative machine learning approach that ensures formal privacy. Most DP-FL approaches ensure DP at the record-level within each silo for cross-silo FL. However, a single user's data may extend across multiple silos, and the desired user-level DP guarantee for such a setting remains unknown. In this study, we present ULDP-FL, a novel FL framework designed to guarantee user-level DP in cross-silo FL where a single user's data may belong to multiple silos. Our proposed algorithm directly ensures user-level DP through per-user weighted clipping, departing from group-privacy approaches. We provide a theoretical analysis of the algorithm's privacy and utility. Additionally, we enhance the algorithm's utility and showcase its private implementation using cryptographic building blocks. Empirical experiments on real-world datasets show substantial improvements in our methods in privacy-utility trade-offs under user-level DP compared to baseline methods. To the best of our knowledge, our work is the first FL framework that effectively provides user-level DP in the general cross-silo FL setting.
翻译:差分隐私联邦学习(DP-FL)作为一种能够保障形式化隐私的协作式机器学习方法,已受到广泛关注。大多数DP-FL方法在跨孤岛联邦学习中,均确保每个孤岛内的记录级差分隐私。然而,单个用户的数据可能跨越多个孤岛,且在此场景下所需的用户级差分隐私保证尚不明确。本研究提出ULDP-FL——一种新型联邦学习框架,旨在保障跨孤岛联邦学习中用户级差分隐私,且单个用户的数据可能属于多个孤岛。我们提出的算法通过逐用户加权裁剪直接确保用户级差分隐私,不同于基于组隐私的方法。我们从理论上分析了该算法的隐私性与实用性。此外,我们通过密码学构建模块增强了算法的实用性,并展示了其私密实现。在真实数据集上的实验表明,与基线方法相比,我们方法在用户级差分隐私下的隐私-效用权衡方面取得了显著改进。据我们所知,本工作是首个在一般跨孤岛联邦学习设定下有效提供用户级差分隐私的联邦学习框架。