Privacy-Protecting, yet Resilient Federated Learning

This invention balances privacy and security in federated learning. It is ideal for privacy-protected machine-learning applications such as diagnosing disease patterns from patient images. With the invention, several cooperating hospitals may for example train a common model without sharing sensitive or protected data and still be assured that only useful updates from the other participants contribute to the model.
Physical Sciences
Reference
b83000
IP right year
2024
IP status
International application filed
Applicant
Technical University of Munich
Contact
Tilo Streibl

Challenge and innovation

In federated learning, a central server shares a common model with several clients, which train the model with local data and provide their resulting model updates to the server. The server then updates and re-shares the model with the clients. To protect against model-inversion attacks and thus increase privacy, the clients may securely aggregate their updates, but this prevents the server from singling out malicious clients or faulty contributions.

The patent-pending technology addresses the previous trade-off between privacy and security by securely pooling the clients into partially overlapping groups. Privacy is ensured by aggregating the updates within each group and revealing only the resulting group updates to the server in unobscured form. Yet, if the groups are composed accordingly, the server may still estimate the performance of individual clients from the performance of the respective groups in which they take part. Suspicious clients can then be excluded from future increments of the common model.

Talk to an expert

Interested in learning more about this technology offer, exploring potential applications or discussing a possible collaboration? Get in touch to learn more.

Tilo Streibl