Federated Learning (FL) is a distributed machine learning approach that safeguards privacy by creating an impartial global model while respecting the privacy of individual client data. However, the conventional FL method can introduce security risks when dealing with diverse client data, potentially compromising privacy and data integrity. To address these challenges, we present a differential privacy (DP) federated deep learning framework in medical image segmentation. In this paper, we extend our similarity weight aggregation (SimAgg) method to DP-SimAgg algorithm, a differentially private similarity-weighted aggregation algorithm for brain tumor segmentation in multi-modal magnetic resonance imaging (MRI). Our DP-SimAgg method not only enhances model segmentation capabilities but also provides an additional layer of privacy preservation. Extensive benchmarking and evaluation of our framework, with computational performance as a key consideration, demonstrate that DP-SimAgg enables accurate and robust brain tumor segmentation while minimizing communication costs during model training. This advancement is crucial for preserving the privacy of medical image data and safeguarding sensitive information. In conclusion, adding a differential privacy layer in the global weight aggregation phase of the federated brain tumor segmentation provides a promising solution to privacy concerns without compromising segmentation model efficacy. By leveraging DP, we ensure the protection of client data against adversarial attacks and malicious participants.
翻译:联邦学习(Federated Learning, FL)是一种分布式机器学习方法,通过构建公平的全局模型来保护隐私,同时尊重个体客户数据的隐私性。然而,传统FL方法在处理异构客户数据时可能引入安全风险,存在隐私泄露和数据完整性受损的潜在问题。为应对这些挑战,我们提出了一种面向医学图像分割的差分隐私(Differential Privacy, DP)联邦深度学习框架。本文在相似性权重聚合(SimAgg)方法的基础上,扩展出DP-SimAgg算法——一种面向多模态磁共振成像(MRI)脑肿瘤分割的差分隐私相似性加权聚合算法。我们的DP-SimAgg方法不仅提升了模型分割能力,还提供了额外的隐私保护层。通过以计算性能为关键考量的广泛基准测试与评估,结果表明DP-SimAgg能够实现准确且鲁棒的脑肿瘤分割,同时最小化模型训练过程中的通信成本。这一进展对于保护医学图像数据的隐私和敏感信息至关重要。总之,在联邦脑肿瘤分割的全局权重聚合阶段引入差分隐私层,为在不牺牲分割模型效能的前提下解决隐私问题提供了有前景的方案。通过利用差分隐私,我们确保了客户数据免受对抗性攻击和恶意参与者的侵害。