联邦学习与数据安全研究综述
2021-07-11王壮壮陈宏松杨丽敏陈丽芳
王壮壮 陈宏松 杨丽敏 陈丽芳
摘 要:数据孤岛是制约人工智能技术发展和落地的主要障碍,随着国家与个人对隐私保护意识的增强,联邦学习在数据不共享的情况下,却能达到数据共享目的,受到广泛关注,联邦学习分为:横向联邦学习、纵向联邦学习和联邦迁移学习,具有数据隔离、质量保证、各参数方地位等同、独立性等优点,但联邦学习也存在很多的安全隐患,本文详细探讨了联邦学习的原理,提出了中央服务器、数据传输、单方数据污染、数据泄露以及对抗攻击等重要的数据安全问题,并汇总介绍了当前主要的防御措施。
关键词: 联邦学习;数据安全;对抗攻击;数据投毒
文章编号: 2095-2163(2021)01-0126-05 中图分类号:TN915.08 文献标志码:A
【Abstract】Data island is the main obstacle that restricts the development and implementation of artificial intelligence technology. With the enhancement of the awareness of privacy protection of the state and individuals, federal learning can achieve the purpose of data sharing without data sharing, which has been widely concerned.Federal learning is divided into horizontal federal learning, vertical federal learning and federal transfer learning. It has the advantages of data isolation, quality assurance, equal status and independence of various parameters, but federal learning also has many security risks. This paper introduces the principle of federal learning in detail, some important data security problems such as central server, data transmission, unilateral data pollution, data leakage and anti-attack are put forward. Meanwhile, the current main defense measures are summarized.
【Key words】federal learning; data security; anti-attack; data poisoning
0 引 言
随着科技、信息化的迅速发展,通过信息共享来对数据进行资源整合是目前常用的一种手段,大数据[1]和人工智能时代[2],AI已经在方方面面得到体现,比如人脸识别、人工智能打败人类围棋手、无人驾驶等等,而经由研究可知,大规模的数据集能够提高AI的性能,数据对于AI的重要性就好比石油对于工业的重要性。然而,生活中大量的数据是私密的、不能共享的,大部分個人和企业所拥有的数据都存在质量较差、数据量有限的问题,只有为数不多的几家公司才能支撑AI技术的实现。个人隐私被窃取、公司数据泄露等安全问题日益凸显,想把分布在各个地方的数据集整合起来几乎是不可能的,或者需要耗费巨大成本。将各……
