arXiv:2409.08372cs.LGcs.AI2024-09中稿 · MLSys 2025

FedProphet让边缘设备高效训练对抗鲁棒的联邦学习,内存减少80%。

FedProphet: Memory-Efficient Federated Adversarial Training via Robust and Consistent Cascade Learning

  • 通过带强凸正则的级联对抗学习降低本地训练内存占用。
  • 在不同设置下性能超越基线,内存降80%,训练速度提升10.8倍。
  • 适合资源受限设备上的可信AI系统部署,兼顾准确率与鲁棒性。

联邦对抗训练(FAT)可为联邦学习(FL)提供对抗样本下的鲁棒性,推动可信AI发展。但FAT需大模型以保持高准确率和强鲁棒性,在内存受限的边缘设备上导致高内存交换延迟。现有内存高效FL方法因本地与全局模型不一致,导致准确率低、鲁棒性弱。本文提出FedProphet,一种新型FAT框架,可同时实现内存效率、鲁棒性和一致性。该方法通过带强凸正则的对抗级联学习,在降低本地训练内存需求的同时保证对抗鲁棒性,并证明强鲁棒性隐含低不一致性。服务器端还设计了训练协调器,包含自适应扰动调整以平衡效用与鲁棒性,以及差异化模块分配以缓解目标不一致。实验显示,FedProphet在不同设置下显著优于其他基线,以80%内存减少和最高10.8倍训练加速,维持了端到端FAT的准确率与鲁棒性。

原文摘要 · Abstract (English)

Federated Adversarial Training (FAT) can supplement robustness against adversarial examples to Federated Learning (FL), promoting a meaningful step toward trustworthy AI. However, FAT requires large models to preserve high accuracy while achieving strong robustness, incurring high memory-swapping latency when training on memory-constrained edge devices. Existing memory-efficient FL methods suffer from poor accuracy and weak robustness due to inconsistent local and global models. In this paper, we propose FedProphet, a novel FAT framework that can achieve memory efficiency, robustness, and consistency simultaneously. FedProphget reduces the memory requirement in local training while guaranteeing adversarial robustness by adversarial cascade learning with strong convexity regularization, and we show that the strong robustness also implies low inconsistency in FedProphet. We also develop a training coordinator on the server of FL, with Adaptive Perturbation Adjustment for utility-robustness balance and Differentiated Module Assignment for objective inconsistency mitigation. FedPeophet significantly outperforms other baselines under different experimental settings, maintaining the accuracy and robustness of end-to-end FAT with 80% memory reduction and up to 10.8x speedup in training time.

联邦学习对抗训练内存优化边缘计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。