5 ms·
Secure aggregation isn’t meaningless, but you’re right that it’s the wrong tool for the problem you’re talking about. The right tool is differential privacy. D
by CyanTas 7y ago
Secure aggregation isn’t meaningless, but you’re right that it’s the wrong tool for the problem you’re talking about. The right tool is differential privacy.
Differential privacy is exactly meant for this, in fact. Differential privacy adds a certain amount of randomly-generated noise to client inputs. The result is that, statistically speaking, it’s impossible to tell the difference between a model with your data in it and a model without your data in it.
Arguably the reason the comic doesn’t mention differential privacy is that it’s neither new nor invented at Google. Or maybe just because it’s not technically part of federated learning. But the “federated learning at scale” paper Google put out mentions it, and says they have implemented DP techniques.
- krick 7y agoThis one is interesting, I'll have to read about that. Right now it doesn't seem to make any sense to me. I mean, if statistically model w/ my data is no different from the model w/o my data, then by definition it must be no better or worse. If it would truly be the case, there wouldn't be any reason to even include the result of such training, would it?
- CyanTas 7y agoI definitely recommend reading more about it because I’m not the best at explaining it. But differential privacy (without federated learning) is what Apple has been doing.