We consider the problem of predicting cellular network performance (signal maps) from measurements collected by several mobile devices. We formulate the problem within the online federated learning framework: (i) federated learning (FL) enables users to collaboratively train a model, while keeping their training data on their devices; (ii) measurements are collected as users move around over time and are used for local training in an online fashion. We consider an honest-but-curious server, who observes the updates from target users participating in FL and infers their location using a deep leakage from gradients (DLG) type of attack, originally developed to reconstruct training data of DNN image classifiers. We make the key observation that a DLG attack, applied to our setting, infers the average location of a batch of local data, and can thus be used to reconstruct the target users' trajectory at a coarse granularity. We build on this observation to protect location privacy, in our setting, by revisiting and designing mechanisms within the federated learning framework including: tuning the FL parameters for averaging, curating local batches so as to mislead the DLG attacker, and aggregating across multiple users with different trajectories. We evaluate the performance of our algorithms through both analysis and simulation based on real-world mobile datasets, and we show that they achieve a good privacy-utility tradeoff.
翻译:摘要:我们研究了利用多个移动设备收集的测量数据,预测蜂窝网络性能(信号地图)的问题。我们在在线联邦学习框架内定义了该问题:(i)联邦学习使用户能够协作训练模型,同时将训练数据保留在设备本地;(ii)随着用户随时间移动,系统持续收集测量数据,并以在线方式用于本地训练。考虑一个诚实但好奇的服务器,该服务器观察参与联邦学习的目标用户上传的更新信息,并利用深度梯度泄露(DLG)类型的攻击推断其位置——此类攻击最初开发用于重构深度神经网络图像分类器的训练数据。我们注意到一个关键现象:在本文场景中应用DLG攻击时,它会推断局部数据批次的平均位置,因此能够以粗粒度方式重构目标用户的轨迹。基于此发现,我们通过重新审视并设计联邦学习框架内的防护机制来保护位置隐私,具体包括:调整用于平均化的联邦学习参数、精心组织局部数据批次以误导DLG攻击者,以及聚合具有不同轨迹的多用户数据。我们基于真实移动数据集通过分析与仿真评估了算法性能,结果表明这些方法能够实现良好的隐私-效用权衡。