How to add noise (differential privacy) to clients weights in federal learning?

Viewed 88

I want to add noise to the gradient on the client side. I modified tf.keras.optimizers.Adam() to DPKerasAdamOptimizer(), but it doesn't work.

    iterative_process = tff.learning.build_federated_averaging_process(
        model_fn=Create_tff_model,
        client_optimizer_fn=lambda: DPKerasAdamOptimizer(1,1.85))

The error is

AssertionError: Neither _compute_gradients() or get_gradients() on the differentially private optimizer was called. This means the training is not differentially private. It may be the case that you need to upgrade to TF 2.4 or higher to use this particular optimizer.

I can add noise on the server side using the tff.learning.model_update_aggregator.dp_aggregator(noise_multiplier, client_per_round), but how to add noise on the client side?

1 Answers

First, have a look at tutorial Differential Privacy in TFF which shows the simple gaussian mechanism using tff.learning.dp_aggregator.

If you would like to customize the details of the mechanism, you can either look at how the dp_aggregator is implemented, in particular tff.aggregators.DifferentiallyPrivateFactory being parameterized by a TensorFlow Privacy object, or write a custom aggregator from scratch.

Note that using DPKerasAdamOptimizer as the client optimizer might not be the right path, as usually the interesting part is to privatize whatever data leaves the client, but the intermediate steps at a client are not important.

Related