Automating model inversion defense selection for heterogeneous federated learning
One example method includes allocating defense methods to nodes of a federation according to respective resources available at the nodes, testing the nodes by causing the defense methods to be run at the nodes, collecting defense method metadata concerning results of running the defense methods at the nodes, analyzing the defense method metadata, and based on the analyzing, allocating the defense methods across the nodes. The defense methods may be configured to defend against a model inversion attack.
1 . A method, comprising:
allocating defense methods, concerning a model inversion attack, to nodes of a federation according to respective resources available at the nodes, and the allocating comprises:
collecting node resource metadata, for each of the nodes, for K federation rounds until a minimum number of nodes is reached for defense method metadata collection;
based on the node resource metadata, performing a constrained resource optimization method that identifies a respective set of defense methods for allocation to each of the nodes, and one of the defense methods is a gradient compression defense;
providing a respective one of the sets of defense methods to each of the nodes;
testing the nodes by causing the respective sets of defense methods to be run at the nodes with respect to respective instances of a model running at the nodes;
collecting defense method metadata concerning results of running the defense methods at the nodes;
analyzing the defense method metadata; and
based on the analyzing, allocating the defense methods across the nodes.
2 . The method as recited in claim 1 , wherein the defense method metadata comprises a quality metric that indicates how well the defense methods performed at the nodes with respect to the model inversion attack.
3 . The method as recited in claim 1 , wherein the defense methods are only allocated to the nodes that have adequate resources available to run the defense methods.
4 . The method as recited in claim 1 , wherein the analyzing comprises applying, to the defense method metadata, a constrained optimization method comprising an objective function that comprises a sum of two functions, wherein the two functions are (1) an average number of the defense methods allocated to each node, and (2) an average number of the nodes allocated to each of the defense methods.
5 . The method as recited in claim 1 , wherein the analyzing of the defense method metadata is performed automatically.
6 . The method as recited in claim 1 , wherein the federation is an element of a heterogeneous federated learning environment.
7 . The method as recited in claim 1 , wherein, given one or more constraints, best ones of the defense methods are allocated across most of the nodes.
8 . A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:
allocating defense methods, concerning a model inversion attack, to nodes of a federation according to respective resources available at the nodes, and the allocating comprises:
collecting node resource metadata, for each of the nodes, for K federation rounds until a minimum number of nodes is reached for defense method metadata collection;
based on the node resource metadata, performing a constrained resource optimization method that identifies a respective set of defense methods for allocation to each of the nodes, and one of the defense methods is a gradient compression defense;
providing a respective one of the sets of defense methods to each of the nodes;
testing the nodes by causing the respective sets of defense methods to be run at the nodes with respect to respective instances of a model running at the nodes;
collecting defense method metadata concerning results of running the defense methods at the nodes;
analyzing the defense method metadata; and
based on the analyzing, allocating the defense methods across the nodes.
9 . The non-transitory storage medium as recited in claim 8 , wherein the defense method metadata comprises a quality metric that indicates how well the defense methods performed at the nodes with respect to the model inversion attack.
10 . The non-transitory storage medium as recited in claim 8 , wherein the defense methods are only allocated to the nodes that have adequate resources available to run the defense methods.
11 . The non-transitory storage medium as recited in claim 8 , wherein the analyzing comprises applying, to the defense method metadata, a constrained optimization method comprising an objective function that comprises a sum of two functions, wherein the two functions are (1) an average number of the defense methods allocated to each node, and (2) an average number of the nodes allocated to each of the defense methods.
12 . The non-transitory storage medium as recited in claim 8 , wherein the analyzing of the defense method metadata is performed automatically.
13 . The non-transitory storage medium as recited in claim 8 , wherein the federation is an element of a heterogeneous federated learning environment.
14 . The non-transitory storage medium as recited in claim 8 , wherein, given one or more constraints, best ones of the defense methods are allocated across most of the nodes.