On the Privacy Leakage of Over-the-Air Federated Learning Over MIMO Fading Channels
GLOBECOM 2023-2023 IEEE Global Communications Conference, 2023•ieeexplore.ieee.org
Federated learning (FL) allows edge devices to collaboratively train machine learning
models without directly sharing data. While over-the-air model aggregation improves
communication efficiency, model uploading can lead to privacy risks. Previous research has
focused on over-the-air FL with a single-antenna server, leveraging communication noise to
enhance user-level privacy. This method achieves the so-called “free” privacy by decreasing
transmit power instead of introducing additional privacy-preserving mechanisms at the …
models without directly sharing data. While over-the-air model aggregation improves
communication efficiency, model uploading can lead to privacy risks. Previous research has
focused on over-the-air FL with a single-antenna server, leveraging communication noise to
enhance user-level privacy. This method achieves the so-called “free” privacy by decreasing
transmit power instead of introducing additional privacy-preserving mechanisms at the …
Federated learning (FL) allows edge devices to collaboratively train machine learning models without directly sharing data. While over-the-air model aggregation improves communication efficiency, model uploading can lead to privacy risks. Previous research has focused on over-the-air FL with a single-antenna server, leveraging communication noise to enhance user-level privacy. This method achieves the so-called “free” privacy by decreasing transmit power instead of introducing additional privacy-preserving mechanisms at the devices. In this paper, we analyze the privacy leakage of over-the-air FL over a multiple-input multiple-output (MIMO) fading channel. We show that FL model aggregation with a multiple-antenna server amplifies privacy leakage. Consequently, relying solely on communication noise is inefficient to meet high privacy requirements, particularly when the receive antenna array is large. This calls for a joint optimization algorithm for the device-side privacy-preserving mechanism and the receiving protocol to achieve a better privacy-learning tradeoff. Numerical results validate our analysis and highlight the impact of the transmit power and the receive antenna array size on the privacy leakage.
ieeexplore.ieee.org
以上显示的是最相近的搜索结果。 查看全部搜索结果