arXiv:2409.17754cs.LGcs.AI2024-09被引 16

提出新聚合算法WFAgg,提升去中心化联邦学习抗恶意攻击能力。

Byzantine-Robust Aggregation for Securing Decentralized Federated Learning

  • 用多滤波器检测并抑制恶意节点干扰
  • 在多种攻击下仍保持模型准确率与收敛性
  • 适合高风险分布式场景下的安全建模

联邦学习(FL)通过在设备本地训练模型缓解隐私问题。去中心化联邦学习(DFL)进一步摒弃中心服务器,增强可扩展性与鲁棒性,避免单点故障。然而,现有多数拜占庭鲁棒算法仅针对中心化场景设计,难以应对DFL的安全挑战。本文提出新型拜占庭鲁棒聚合算法WFAgg,通过多重滤波机制识别并抑制恶意行为,在动态去中心化拓扑中同时提升系统鲁棒性。实验表明,该算法在多种拜占庭攻击下仍能保持模型准确率与收敛性,优于主流中心化方案(如Multi-Krum、Clustering)。评估基于IID图像分类任务,在中心化与去中心化场景下均验证有效性。

原文摘要 · Abstract (English)

Federated Learning (FL) emerges as a distributed machine learning approach that addresses privacy concerns by training AI models locally on devices. Decentralized Federated Learning (DFL) extends the FL paradigm by eliminating the central server, thereby enhancing scalability and robustness through the avoidance of a single point of failure. However, DFL faces significant challenges in optimizing security, as most Byzantine-robust algorithms proposed in the literature are designed for centralized scenarios. In this paper, we present a novel Byzantine-robust aggregation algorithm to enhance the security of Decentralized Federated Learning environments, coined WFAgg. This proposal handles adverse conditions and strengthens the robustness of dynamic decentralized topologies at the same time by employing multiple filters to identify and mitigate Byzantine attacks. Experimental results demonstrate the effectiveness of the proposed algorithm in maintaining model accuracy and convergence in the presence of various Byzantine attack scenarios, outperforming state-of-the-art centralized Byzantine-robust aggregation schemes (such as Multi-Krum or Clustering). These algorithms are evaluated on an IID image classification problem in both centralized and decentralized scenarios.

联邦学习拜占庭鲁棒去中心化安全聚合

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。