arXiv:2409.15067cs.LGcs.CR2024-09被引 9

提出分层联邦学习框架,有效防御边缘设备中的模型投毒攻击。

SHFL: Secure Hierarchical Federated Learning Framework for Edge Networks

  • 在边缘层筛选参与训练的设备,降低恶意节点影响。
  • 采用凸优化方法聚合边缘模型,提升全局模型抗攻击能力。
  • 适合物联网与边缘计算中隐私敏感场景的高安全需求。

联邦学习(FL)是一种适用于资源受限设备上运行、数据分布非独立同分布(non-IID)的隐私敏感应用的分布式机器学习范式。传统FL采用客户端-服务器模型,通过单层聚合(AGR)过程由服务器整合所有客户端的本地模型以构建全局模型。然而,该方法易受模型/数据投毒攻击。近年来,随着物联网(IoT)和边缘计算的发展,分层联邦学习系统应运而生,具备边缘与云服务器双层聚合机制。本文提出一种安全分层联邦学习框架(SHFL),以应对分层边缘网络中的投毒攻击。SHFL在边缘层聚合模型,引入两项新方法:1)在边缘侧运行客户端选择算法,筛选参与训练的物联网设备;2)基于凸优化理论设计模型聚合方法,降低受攻击边缘网络对全局模型(云端)聚合结果的影响。评估结果表明,相比现有先进方法,SHFL在存在客户端投毒攻击时显著提升了全局模型的最大准确率。

原文摘要 · Abstract (English)

Federated Learning (FL) is a distributed machine learning paradigm designed for privacy-sensitive applications that run on resource-constrained devices with non-Identically and Independently Distributed (IID) data. Traditional FL frameworks adopt the client-server model with a single-level aggregation (AGR) process, where the server builds the global model by aggregating all trained local models received from client devices. However, this conventional approach encounters challenges, including susceptibility to model/data poisoning attacks. In recent years, advancements in the Internet of Things (IoT) and edge computing have enabled the development of hierarchical FL systems with a two-level AGR process running at edge and cloud servers. In this paper, we propose a Secure Hierarchical FL (SHFL) framework to address poisoning attacks in hierarchical edge networks. By aggregating trained models at the edge, SHFL employs two novel methods to address model/data poisoning attacks in the presence of client adversaries: 1) a client selection algorithm running at the edge for choosing IoT devices to participate in training, and 2) a model AGR method designed based on convex optimization theory to reduce the impact of edge models from networks with adversaries in the process of computing the global model (at the cloud level). The evaluation results reveal that compared to state-of-the-art methods, SHFL significantly increases the maximum accuracy achieved by the global model in the presence of client adversaries applying model/data poisoning attacks.

联邦学习边缘计算安全投毒攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。