Geometric Data Perturbation with Noisy-Anchor Alignment for Privacy-Preserving Collaborative Learning
Organizations: Graduate School of Science and Technology, University of Tsukuba, 1-1-1, Tennodai, Tsukuba, 305-8573, Ibaraki, Japan · Institute of Systems and Information Engineering, University of Tsukuba, 1-1-1, Tennodai, Tsukuba, 305-8573, Ibaraki, Japan · Center for Artificial Intelligence Research, Tsukuba Institute for Advanced Research (TIAR), University of Tsukuba, 1-1-1, Tennodai, Tsukuba, 305-8577, Ibaraki, Japan
Abstract
Geometric data perturbation enables one-shot representation sharing for privacy-preserving collaborative learning: each participant applies a secret distance-preserving transformation to its private data and uploads the resulting representation to a central analyst. We study analyst-participant collusion, in which a colluding participant discloses its data and transformation to help the analyst reconstruct another participant's data. Independent participant-specific transformations block direct inversion through a disclosed common transformation but leave uploads in incompatible coordinate systems, degrading pooled learning. Data Collaboration analysis restores compatibility by aligning transformed copies of a common anchor matrix withheld from the analyst. We show that, when the centered anchor matrix has full column rank, a colluder who discloses it enables exact recovery of every participant's transformation and inversion of noiseless private representations. Adding noise to private-data representations leaves this transformation-recovery channel intact and reduces leakage at a substantial utility cost. Instead, we perturb the anchor representations: each participant perturbs only its transformed anchor representation, preserving the geometry of its private-data upload while turning known-anchor transformation recovery into a noisy estimation problem. The analyst estimates the alignment using a spectral estimator for a generalized orthogonal Procrustes problem. We analyze recovery attacks against this protocol and compare both noise placements on the CelebA and VGGFace2 facial image datasets. Under the evaluated collusion attacks, noisy-anchor alignment retains higher downstream accuracy at low identity-linkage levels. Participant-count experiments examine the utility gains and limitations of larger collaborations at comparable measured linkage.
Figures & tables
| Method | Private-data upload | Anchor upload |
|---|---|---|
| Local | — | — |
| C-GDP | — | |
| C-GDP (private-data noise) | — | |
| I-GDP | — | |
| NAA-GDP |
| Stage | Output dimensions |
|---|---|
| Reshape | |
| Convolution 1, ReLU | |
| Max pooling 1 | |
| Convolution 2, ReLU | |
| Max pooling 2 | |
| Flatten |
Appendix figures & tables1 asset
Supplementary material from the paper’s appendix.