Source-linked AI summary

A system-theoretic framework for privacy preservation in continuous-time multiagent dynamics

Claudio Altafini

arXiv:1904.11246v2eess.SYmath.OC

TL;DR

The paper addresses how multiagent systems can exchange information for distributed computation without revealing agents’ initial states. It proposes local, time-varying output masks and analyzes the resulting masked dynamics. The masked system preserves the original attractor, but privacy requires time variation and the absence of fixed points.

  • Problem

    Multiagent collaboration requires exchanging information, creating the problem of protecting agents’ initial states during distributed computation.

  • Method

    The paper uses agent-local, hidden, time-varying output masks that offset initial conditions and asymptotically converge to the true states.

  • Results

    The masked system globally converges to the same attractor as the unmasked system across the analyzed stable, consensus, opinion-dynamics, and synchronization settings.

  • Takeaways & Limitations

    Dynamical privacy preserves distributed convergence, but the masked system must remain time-varying and have no fixed points to avoid initial-state disclosure.

  • Takeaways & Limitations

    The framework requires non-completely-covering neighborhoods, an assumption the authors describe as restrictive.

Abstract

from arXiv · show

In multiagent dynamical systems, privacy protection corresponds to avoid disclosing the initial states of the agents while accomplishing a distributed task. The system-theoretic framework described in this paper for this scope, denoted dynamical privacy, relies on introducing output maps which act as masks, rendering the internal states of an agent indiscernible by the other agents as well as by external agents monitoring all communications. Our output masks are local (i.e., decided independently by each agent), time-varying functions asymptotically converging to the true states. The resulting masked system is also time-varying, and has the original unmasked system as its limit system. When the unmasked system has a globally exponentially stable equilibrium point, it is shown in the paper that the masked system has the same point as a global attractor. It is also shown that existence of equilibrium points in the masked system is not compatible with dynamical privacy. Application of dynamical privacy to popular examples of multiagent dynamics, such as models of social opinions, average consensus and synchronization, is investigated in detail.

1 Introduction

The paper introduces dynamical privacy for continuous-time multiagent systems: local, hidden output masks protect initial states while preserving distributed convergence. The framework applies to globally stable systems, average consensus, opinion dynamics, and pinning synchronization, but privacy requires time-varying masked dynamics without fixed points.

  • Framework: The framework uses local, time-varying output masks to hide agents’ initial states while preserving the distributed computation asymptotically.The masks are independently chosen by agents, and their convergence to the true state makes the masked dynamics converge toward the original dynamics.
  • Main result: Under suitable neighborhood assumptions, masked systems converge globally and uniformly to the same attractor as the unmasked system while preserving initial-state privacy.This applies to globally exponentially stable systems and systems with exponential stability on initial-condition-dependent slices, such as consensus.
  • Dynamical consequences: Privacy requires a time-varying masked system with no fixed points, even though its original unmasked system is recovered as a limit system.The absence of fixed points prevents stationary messages from revealing initial conditions near an attractor.
  • Applications: The paper analyzes privacy-preserving versions of a globally exponentially stable nonlinear system, average consensus, and pinning synchronization.In all three cases, the masked system has the unmasked equilibrium as a unique attractor but is not stable at that attractor because it lacks fixed points.
  • Analysis: The convergence analysis uses Lyapunov arguments whose derivatives are upper bounded by terms that decay to zero, despite being generally sign indefinite.For pinning synchronization, the unmasked and limiting systems may themselves be time-varying.
  • Applications: Privacy concerns also arise in continuous-time Friedkin-Johnsen opinion dynamics because the equilibrium depends on the initial conditions.The initial-condition-dependent inhomogeneous term is added to an asymptotically stable linear system.

2 Preliminaries

The preliminaries define stability and asymptotic concepts for continuous-time, possibly time-varying systems. They introduce equilibria, uniform global attractivity, limit systems, and omega-limit sets used to analyze masked dynamics.

  • Comparison functions: Class K∞, L, and KL_e functions encode increasing, decreasing-to-zero, and state-time decay properties used in stability estimates.The exponential subclasses use forms such as ζ(t)=ae^(-δt) and β(r,t)=arie^(-δt).
  • Stability concepts: An equilibrium is a point where the time-varying vector field vanishes almost everywhere, while uniform global attractivity requires all trajectories to approach that point uniformly over initial times and states.A point may be attractive without being an equilibrium, a distinction used extensively in the paper.
  • Limit systems: A limit system is obtained when time-translated vector fields converge along a sequence of shifts tending to infinity.The preliminaries state an existence condition based on uniform continuity and boundedness.
  • Limit sets: The omega-limit set contains subsequential limits of a trajectory and is nonempty, compact, and approached when the trajectory is bounded.For time-varying systems, omega-limit sets need not be invariant; invariance may hold only for limit systems and can still fail for asymptotically autonomous systems.

3 Problem formulation

The problem formulation models distributed continuous-time dynamics on a graph and inserts agent-local output masks before communication. Privacy masks must hide initial states, avoid preserving neighborhoods, and asymptotically converge to the true states without creating spurious equilibria.

  • 3 Problem formulation: Each agent’s dynamics depend on its own state and essential in-neighbors, under Lipschitz, existence, graph, and neighborhood assumptions.The target systems include globally exponentially stable equilibria and initial-condition-dependent exponentially stable manifolds.
  • 3 Problem formulation: The privacy problem is to compute the system’s attractor distributively while preventing neighboring agents from learning the agents’ initial conditions.Directly exchanging state values cannot provide this privacy, so the paper inserts time-varying output maps before communication.
  • 3.1 Output masks: A local mask has the form h_i(t,x_i,π_i), allowing each agent to choose its transformation and keep its functional form and parameters private.The masked output y=h(t,x,π) is transmitted to first out-neighbors, while the state and mask remain private.
  • 3.1 Output masks: Privacy masks must alter every initial state, avoid preserving neighborhoods, and be strictly increasing in each state variable.These properties prevent fixed points and help avoid undesired behavior such as spurious equilibria.
  • 3.1 Output masks: A vanishing privacy mask makes the masking perturbation decrease over time and converges to the true state for fixed mask parameters.The paper separately defines the decreasing-in-time perturbation property and the limit h_i(t,x_i,π_i)→x_i.
  • 3.1 Output masks: The privacy metric measures the initial discrepancy between the masked and true outputs for each agent and takes the minimum across agents for the system.For agent i, it is defined as ρ_i(x_o,i)=|h_i(0,x_o,i,π_i)−x_o,i|.
  • 3.2 Examples of output masks: The paper’s mask examples illustrate how local, time-varying transformations are constructed for the distributed setting.The examples are introduced after the formal privacy-mask and vanishing-mask definitions.

Linear mask

The linear mask example is not a proper privacy mask because it leaves the origin unchanged. This reflects a broader limitation of homogeneous maps: they cannot escape neighborhoods of zero.

  • Linear mask: The linear mask fails to provide privacy because h_i(0,0,π_i)=0, so the origin is not masked.The passage notes that homogeneous maps share this limitation and fail to escape neighborhoods of x_i.
  • Linear mask: Homogeneous maps cannot escape neighborhoods of the origin, making them unsuitable when privacy requires neighborhood non-preservation.This limitation follows from the same fixed-origin behavior identified in the example.

Additive mask

The additive mask offsets each transmitted state by a locally chosen, exponentially decaying term, and is classified as vanishing.

  • The mask adds γ_i e^-δ_i t to x_i, with δ_i > 0 and γ_i ≠ 0.
  • Because the added term decays over time, this additive privacy mask is vanishing.

Affine mask

The affine mask scales the additively masked state by c_i > 1 and remains a privacy mask even though it is not vanishing.

  • The affine mask applies c_i(x_i + γ_i e^-δ_i t), with c_i > 1, δ_i > 0, and γ_i ≠ 0.
  • Its output converges to c_i x_i rather than x_i, so the mask is privacy-preserving but not vanishing.

Vanishing affine mask

The vanishing affine mask is a locally configurable privacy mechanism embedded in a continuous-time masked system. Dynamical privacy combines indiscernibility with convergent outputs, but excludes equilibrium points while preserving the unmasked system as a limit under sufficient conditions.

  • Vanishing affine mask: The vanishing affine mask uses positive φ_i, σ_i, and δ_i with nonzero γ_i, and its vector form uses diagonal parameter matrices.
  • Vanishing affine mask: For masks (8), (9), and (10), agents can choose local parameters so that ρ(x_o) > λ for any λ > 0 and any initial state.
  • Dynamically private systems: Indiscernibility treats recovery of an agent’s initial state as a joint system-identification and observability problem, not ordinary state observability.
  • Dynamically private systems: Under no completely covering neighborhoods, conditions defining dynamical privacy imply that the masked system is dynamically private.
  • Dynamically private systems: A dynamically private system cannot have equilibrium points; with a vanishing mask, it is asymptotically autonomous with the unmasked system as limit system.

4 Dynamical privacy in globally exponentially stable systems

Output masks preserve privacy while retaining the original system’s attractor behavior. For globally exponentially stable systems and the Friedkin–Johnsen model, the masked dynamics remain private and converge to the appropriate unmasked attractor.

  • 4 Dynamical privacy in globally exponentially stable systems: Theorem 1 establishes that an affine masked system is dynamically private and uniformly globally attractive to the original equilibrium x∗=0.The result assumes a globally Lipschitz system, Assumption 1, and global exponential stability of the unmasked equilibrium.
  • 4 Dynamical privacy in globally exponentially stable systems: Privacy masks eliminate fixed points in the masked system, so x∗ remains an attractor but cannot be treated as a stable equilibrium.The inhomogeneous mask prevents x∗=0 from being stationary.
  • 4 Dynamical privacy in globally exponentially stable systems: The masked system is asymptotically autonomous, has the unmasked system as its limit system, and every trajectory has ω-limit set {0}.The affine mask may be nonvanishing, so the masked and unmasked systems differ even though they share the same attractor.
  • 4 Dynamical privacy in globally exponentially stable systems: For the saturated nonlinear example, κ < 1/ρ(A) makes x∗=0 globally exponentially stable, while n=100 simulations show masked outputs converging toward private states.The initial output-state gap satisfies ρ_i(x_o,i)=|y_i(0)−x_i(0)|≥1 and decreases to 0.
  • 4.1 Application to continuous-time Friedkin-Johnsen model: In the Friedkin–Johnsen model, the attractor x∗(x_o)=(L+Θ)^−1Θx_o depends on the initial condition, requiring a vanishing mask for correct convergence.The masked system remains dynamically private and globally uniformly attractive to x∗(x_o).

5 Dynamically private average consensus

The privacy-preserving consensus system hides initial states while preserving the average-consensus attractor. Its time-varying masked dynamics converge to η1, although the masked system has no equilibria and obscures the conservation law.

  • 5 Dynamically private average consensus: The masked consensus system has η1 as a global uniform attractor on span(1)⊥ and is dynamically private under Assumption 1.Here η=1^T x_o/n is the average consensus value.
  • 5 Dynamically private average consensus: The masked system is asymptotically autonomous with the unmasked consensus system as its limit system, and each trajectory has ω-limit set {η1}.This preserves the consensus limit despite the time-varying privacy mask.
  • 5 Dynamically private average consensus: Privacy removes equilibria from the masked system, so η1 remains an attractor without being a stable equilibrium.The extra inhomogeneous term prevents standard equilibrium stability from applying.
  • 5 Dynamically private average consensus: The exact privacy-preserving consensus construction requires n>2 because the dynamics are restricted to the n−1 dimensional subspace span(1)⊥.The n=2 case cannot satisfy Assumption 1 when L is irreducible.
  • 5 Dynamically private average consensus: For n=100 agents, masked and private states converge to η=1^T x(0)/n, while y(0) hides x(0) and the masked average is not conserved.The mask can obscure initial neighborhoods and the conservation law during transients.

6 Privacy for higher order systems: the case of pinned synchronization

The framework extends dynamical privacy to pinned synchronization of higher-order nonlinear agents, including time-varying exosystems. Under stated Lipschitz, graph, boundedness, and matrix conditions, the exosystem is a global attractor despite the masked system lacking fixed points.

  • Privacy masks: The output-mask formalism extends to vector states through diagonal time-varying maps, with the resulting masked system converging to the time-varying pinned limit system.This case is not asymptotically autonomous because the limit system depends on the exosystem.
  • Model: Pinned synchronization couples higher-order agents through an irreducible Laplacian, positive-definite inner coupling, and pinned nodes driven by an exosystem.The exosystem obeys ˙s = f(s) and may represent an equilibrium, periodic, or chaotic system.
  • Theorem 4: Under Assumptions 1 and 2, bounded exosystem trajectories, irreducible coupling, and the matrix condition ensure the exosystem is a global attractor.The result applies to the dynamically private system and its pinned synchronization dynamics.
  • Example 3: The consensus visualization separates private states, masked outputs, initial conditions, and the disagreement measure Vmm(t).It also compares the averages 1T x(t)/n and 1T y(t)/n.
  • Example 4: For a three-dimensional chaotic attractor, n = 50 coupled agents synchronize privately to an exosystem obeying the same law, while mask parameters tune convergence speed.The privacy measure in this example is λ = 10.

7 Conclusions

The conclusions characterize exact privacy as requiring restrictive neighborhood conditions and explain that privacy is incompatible with fixed points. They identify discrete-time systems, finite-time masks, time-varying graphs, and weaker stability regimes as open extensions.

  • Conclusions: The non-completely-covering neighborhood assumption is restrictive but is key to preventing eavesdroppers from identifying the system model and observing initial states.A privacy breach at one node does not compromise the other nodes.
  • Conclusions: Privacy is incompatible with fixed points because stationary messages can reveal an agent’s initial state when all agents begin at the fixed point.The conclusion extends this concern to approximate privacy at any accuracy level.
  • Future work: The framework’s proposed generalizations include discrete-time systems and masks that vanish in finite time, while time-varying communication graphs and multiple isolated equilibria remain more challenging.The stated stability setting is global exponential stability, possibly on state-space slices when equilibria form a continuum.

A Appendix

The appendix supplies comparison and Lyapunov tools for proving convergence, privacy, and limit-system properties of masked dynamics. It also establishes indiscernibility and the absence of equilibria under the paper’s mask assumptions.

  • Auxiliary lemmas: A scalar comparison system with exponentially decaying perturbations remains bounded and converges to zero, supporting the appendix’s time-varying Lyapunov convergence argument.The comparison dynamics preserve nonnegativity and satisfy lim t→∞v(t) = 0.
  • Auxiliary lemmas: The Lyapunov lemma converts a derivative bounded by decaying terms into uniform global convergence of the time-varying system to the origin.The proof uses the scalar comparison result with initial condition v(to) = V(to, xo).
  • Privacy proof: Indiscernibility follows because an observing agent cannot invert the unknown mask, identify its parameters from incomplete neighborhoods, or correctly estimate the required integral.Thus neither static nor dynamical estimation of the private initial condition succeeds.
  • Equilibria and convergence: The masked system cannot have equilibrium points under the privacy-mask properties, since a time-invariant masked equilibrium would contradict asymptotic convergence and privacy.The appendix also establishes convergence results for masked versions of stable systems and consensus dynamics.
  • Limit systems: The appendix shows that masked dynamics converge to the unmasked limit system on compact sets because the output masks converge uniformly to the identity along suitable time sequences.For each component, fi(h(t, x, π)) converges uniformly on compact sets to fi(x).
Loading 1904.11246v2…