HPFL: Hybrid Privacy-Preserving Federated Learning Framework Based on Homomorphic Encryption and Differential Privacy
Abstract
Federated Learning (FL) enables model training on distributed data without the disclosure of private information. However, it is still vulnerable to malicious aggregators in FL. Existing Differential Privacy (DP) methods suffer from accuracy degradation due to noise injections. While Homomorphic Encryption (HE) schemes have no model accuracy loss, they need tremendous computation overheads, especially for a large model, which slows down FL convergence time. Moreover, existing hybrid DP and HE schemes suffers from low accuracy and high computation complexity. To this end, this paper proposes a hybrid privacy-preserving FL (HPFL) framework that dynamically integrates HE with DP at each device's side. We formulate this issue as a utility maximization problem under the consideration of time consumption for both model training and model protections within each global training round. A closed-form optimal HE ratio for each device is theoretically derived, and a model gradient magnitude-based mask is further designed to determine the HE-based model parameters. Extensive experiments on FMNIST, CIFAR-10, and STL-10 demonstrate that the proposed HPFL significantly outperforms DP method only with accuracy improvements of up to 30%. Moreover, our proposed HPFL can significantly reduce the overall training time of FL by approximately 80%, while suffering from 3% accuracy loss, compared with HE only.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.