Geometric Data Perturbation with Noisy-Anchor Alignment for Privacy-Preserving Collaborative Learning

📅 2026-08-19
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出在共享锚点表示中添加噪声的方法,以解决隐私保护协作学习中的数据恢复攻击问题,同时保持模型性能。
📝 Abstract
Geometric Data Perturbation (GDP) enables one-shot, privacy-preserving collaborative learning: each participant applies a distance-preserving transformation to its private data and uploads only the resulting representation to a central analyst. We study GDP under analyst-participant collusion, in which the analyst combines all uploaded representations with the private data and transformations disclosed by colluding participants to recover a non-colluding participant's private data. Participant-specific independent transformations resist this attack but map participants' data into incompatible representation spaces, degrading downstream model performance. Shared-anchor alignment from Data Collaboration (DC) analysis restores compatibility and improves utility, but we show that disclosing the DC anchor matrix enables exact recovery of non-colluding participants' private data even in the presence of collusion. Adding noise directly to the private-data representations mitigates this vulnerability but substantially reduces utility. We propose adding noise to the anchor representations instead. Each participant independently transforms its private data and the shared anchor matrix, perturbs only the resulting anchor representation, and uploads both representations in a single round. Using the noisy anchor representations, the analyst aligns the private-data representations by solving a Generalized Orthogonal Procrustes Problem. We characterize alignment and recovery errors, specialize a conservative sufficient condition for convergence of the alignment to our setting, and analyze three recovery attacks. Experiments on MNIST and CelebA show that, across the evaluated attacks and deployment settings, anchor noise achieves higher learning accuracy than private-data noise at comparable measured leakage, yielding a more favorable privacy-utility trade-off under the specified collusion model.
Problem

Research questions and friction points this paper is trying to address.

Geometric Data Perturbation
Privacy-Preserving Collaborative Learning
Collusion
Data Compatibility
Model Performance
Innovation

Methods, ideas, or system contributions that make the work stand out.

Geometric Data Perturbation
Noisy-Anchor Alignment
Generalized Orthogonal Procrustes Problem
Privacy-Preserving Collaborative Learning
🔎 Similar Papers
2024-08-30Journal of Information Security and ApplicationsCitations: 0
K
Keiyu Nosaka
Graduate School of Science and Technology, University of Tsukuba, 1-1-1, Tennodai, Tsukuba, 305-8573, Ibaraki, Japan
Y
Yamato Suetake
Graduate School of Science and Technology, University of Tsukuba, 1-1-1, Tennodai, Tsukuba, 305-8573, Ibaraki, Japan
Y
Yuichi Takano
Institute of Systems and Information Engineering, University of Tsukuba, 1-1-1, Tennodai, Tsukuba, 305-8573, Ibaraki, Japan; Center for Artificial Intelligence Research, Tsukuba Institute for Advanced Research (TIAR), University of Tsukuba, 1-1-1, Tennodai, Tsukuba, 305-8577, Ibaraki, Japan
Y
Yukihiko Okada
Institute of Systems and Information Engineering, University of Tsukuba, 1-1-1, Tennodai, Tsukuba, 305-8573, Ibaraki, Japan; Center for Artificial Intelligence Research, Tsukuba Institute for Advanced Research (TIAR), University of Tsukuba, 1-1-1, Tennodai, Tsukuba, 305-8577, Ibaraki, Japan
Akiko Yoshise
Akiko Yoshise
University of Tsukuba
Mathematical OptimizationOperations Research