Federated learning (FL) emerged as a paradigm designed to improve data privacy by enabling data to reside at its source, thus embedding privacy as a core consideration in FL architectures, whether centralized or decentralized. Contrasting with recent findings by Pasquini et al., which suggest that decentralized FL does not empirically offer any additional privacy or security benefits over centralized models, our study provides compelling evidence to the contrary. We demonstrate that decentralized FL, when deploying distributed optimization, provides enhanced privacy protection - both theoretically and empirically - compared to centralized approaches. The challenge of quantifying privacy loss through iterative processes has traditionally constrained the theoretical exploration of FL protocols. We overcome this by conducting a pioneering in-depth information-theoretical privacy analysis for both frameworks. Our analysis, considering both eavesdropping and passive adversary models, successfully establishes bounds on privacy leakage. We show information theoretically that the privacy loss in decentralized FL is upper bounded by the loss in centralized FL. Compared to the centralized case where local gradients of individual participants are directly revealed, a key distinction of optimization-based decentralized FL is that the relevant information includes differences of local gradients over successive iterations and the aggregated sum of different nodes' gradients over the network. This information complicates the adversary's attempt to infer private data. To bridge our theoretical insights with practical applications, we present detailed case studies involving logistic regression and deep neural networks. These examples demonstrate that while privacy leakage remains comparable in simpler models, complex models like deep neural networks exhibit lower privacy risks under decentralized FL.
翻译:联邦学习(FL)作为一种旨在通过使数据保留在其源头来改善数据隐私的范式而出现,从而将隐私作为FL架构(无论是中心化还是去中心化)的核心考量。与Pasquini等人最近的研究结果(该结果表明去中心化FL在经验上并未比中心化模型提供任何额外的隐私或安全优势)形成对比,我们的研究提供了相反的有力证据。我们证明,与中心化方法相比,采用分布式优化的去中心化FL在理论上和经验上都提供了增强的隐私保护。通过迭代过程量化隐私损失的挑战传统上制约了对FL协议的理论探索。我们通过为两种框架进行开创性的深度信息论隐私分析来克服这一挑战。我们的分析考虑了窃听和被动对手模型,成功地建立了隐私泄露的界限。我们从信息论上证明,去中心化FL中的隐私损失以中心化FL中的损失为上界。与中心化情况下直接暴露个体参与者的局部梯度相比,基于优化的去中心化FL的一个关键区别在于,相关信息包括连续迭代间局部梯度的差异以及网络中不同节点梯度的聚合和。这种信息使对手推断私有数据的尝试变得复杂。为了将我们的理论见解与实际应用联系起来,我们提供了涉及逻辑回归和深度神经网络的详细案例研究。这些例子表明,虽然在较简单的模型中隐私泄露程度相当,但在去中心化FL下,像深度神经网络这样的复杂模型表现出更低的隐私风险。