Secure Shapley Value for Cross-Silo Federated Learning (Technical Report)
arXiv:2209.04856 · doi:10.14778/3587136.3587141
Abstract
The Shapley value (SV) is a fair and principled metric for contribution evaluation in cross-silo federated learning (cross-silo FL), wherein organizations, i.e., clients, collaboratively train prediction models with the coordination of a parameter server. However, existing SV calculation methods for FL assume that the server can access the raw FL models and public test data. This may not be a valid assumption in practice considering the emerging privacy attacks on FL models and the fact that test data might be clients' private assets. Hence, we investigate the problem of secure SV calculation for cross-silo FL. We first propose HESV, a one-server solution based solely on homomorphic encryption (HE) for privacy protection, which has limitations in efficiency. To overcome these limitations, we propose SecSV, an efficient two-server protocol with the following novel features. First, SecSV utilizes a hybrid privacy protection scheme to avoid ciphertext--ciphertext multiplications between test data and models, which are extremely expensive under HE. Second, an efficient secure matrix multiplication method is proposed for SecSV. Third, SecSV strategically identifies and skips some test samples without significantly affecting the evaluation accuracy. Our experiments demonstrate that SecSV is 7.2-36.6 times as fast as HESV, with a limited loss in the accuracy of calculated SVs.
Technical report for our VLDB 2023 paper (https://www.vldb.org/pvldb/vol16/p1657-zheng.pdf)
References in corpus (7)
- Federated Learning: Challenges, Methods, and Future Directions
- Secure Federated Transfer Learning
- Inverting Gradients -- How easy is it to break privacy in federated learning?
- LightSecAgg: a Lightweight and Versatile Design for Secure Aggregation in Federated Learning
- Local Differential Privacy based Federated Learning for Internet of Things
- Turbo-Aggregate: Breaking the Quadratic Aggregation Barrier in Secure Federated Learning
- deepTarget: End-to-end Learning Framework for microRNA Target Prediction using Deep Recurrent Neural Networks