Papers
Topics
Authors
Recent
Search
2000 character limit reached

The Fundamental Price of Secure Aggregation in Differentially Private Federated Learning

Published 7 Mar 2022 in cs.LG and stat.ML | (2203.03761v1)

Abstract: We consider the problem of training a dd dimensional model with distributed differential privacy (DP) where secure aggregation (SecAgg) is used to ensure that the server only sees the noisy sum of nn model updates in every training round. Taking into account the constraints imposed by SecAgg, we characterize the fundamental communication cost required to obtain the best accuracy achievable under ε\varepsilon central DP (i.e. under a fully trusted server and no communication constraints). Our results show that O~(min(n<sup>2ε<sup>2,</sup></sup>d))\tilde{O}\left( \min(n<sup>2\varepsilon<sup>2,</sup></sup> d) \right) bits per client are both sufficient and necessary, and this fundamental limit can be achieved by a linear scheme based on sparse random projections. This provides a significant improvement relative to state-of-the-art SecAgg distributed DP schemes which use O~(dlog(d/ε<sup>2))\tilde{O}(d\log(d/\varepsilon<sup>2)) bits per client. Empirically, we evaluate our proposed scheme on real-world federated learning tasks. We find that our theoretical analysis is well matched in practice. In particular, we show that we can reduce the communication cost significantly to under $1.2$ bits per parameter in realistic privacy settings without decreasing test-time performance. Our work hence theoretically and empirically specifies the fundamental price of using SecAgg.

Citations (58)

Summary

No one has generated a summary of this paper yet.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We haven't generated a list of open problems mentioned in this paper yet.

Continue Learning

We haven't generated follow-up questions for this paper yet.