arXiv:cs.LG· Hao Liang, Haifeng Wen, Kaishun Wu, Khaled B. Letaief, Hong Xing·· 5 小时前AI 评分30
无需注入人工噪声:多天线基站多址衰落信道下联邦学习的差分隐私增益
Differential Privacy as a Perk: Federated Learning over Multiple-Access Fading Channels with a Multi-Antenna Base Station
AI 导读
针对多天线基站多址衰落信道下的空中联邦学习(AirFL),研究证明在用户级差分隐私(DP)要求下无需注入人工噪声(AN)即可获得DP增益,推翻了此前同类设置中必须注入AN的结论。作者推导出在一般有界域假设下收敛的DP新界,以及针对一般光滑非凸损失函数的收敛界,并通过优化接收波束成形与功率分配刻画最优收敛-隐私权衡,给出DP可在不损害训练的前提下实现的显式条件。
正文
Abstract:Federated Learning (FL) is a distributed learning paradigm that preserves privacy by eliminating the need to exchange raw data during training. In its prototypical edge instantiation with underlying wireless transmissions enabled by analog over-the-air computing (AirComp), referred to as \emph{over-the-air FL (AirFL)}, the inherent channel noise plays a unique role of \emph{frenemy} in the sense that it degrades training due to noisy global aggregation while providing a natural source of randomness for privacy-preserving mechanisms, formally quantified by \emph{differential privacy (DP)}. It remains, nevertheless, challenging to effectively harness such channel impairments, as prior arts, under assumptions of either simple channel models or restricted types of loss functions, mostly considering (local) DP enhancement with a single-round or non-convergent bound on privacy loss. In this paper, we study AirFL over multiple-access fading channels with a multi-antenna base station (BS) subject to user-level DP requirements. Despite a recent study, which claimed in similar settings that artificial noise (AN) must be injected to ensure DP in general, we demonstrate, on the contrary, that DP can be gained as a \emph{perk} even \emph{without} employing any AN. Specifically, we derive a novel bound on DP that converges under general bounded-domain assumptions on model parameters, along with a convergence bound with general smooth and non-convex loss functions. Next, we optimize over receive beamforming and power allocations to characterize the optimal convergence-privacy trade-offs, which also reveal explicit conditions in which DP is achievable without compromising training. Finally, our theoretical findings are validated by extensive numerical results.
| Comments: | 20 pages, 8 figures |
| Subjects: | Machine Learning (cs.LG); Cryptography and Security (cs.CR); Machine Learning (stat.ML) |
| Cite as: | arXiv:2510.23463 [cs.LG] |
| (or arXiv:2510.23463v4 [cs.LG] for this version) | |
| https://doi.org/10.48550/arXiv.2510.23463 arXiv-issued DOI via DataCite |
Submission history
From: Hao Liang [view email]
[v1]
Mon, 27 Oct 2025 16:01:15 UTC (372 KB)
[v2]
Wed, 29 Oct 2025 11:16:37 UTC (373 KB)
[v3]
Thu, 15 Jan 2026 17:38:48 UTC (502 KB)
[v4]
Fri, 2 Oct 2026 04:35:47 UTC (1,665 KB)
来源:arXiv:cs.LG · arxiv.org