arXiv:2409.20329cs.LGcs.CR2024-09NeurIPS被引 11

对抗性客户端下,微调个性化模型比全协作更有效。

Fine-Tuning Personalization in Federated Learning to Mitigate Adversarial Clients

  • 提出插值式个性化联邦学习框架,平衡协作与个性化。
  • 实证显示:在存在恶意客户端时,完全协作性能反而更差。
  • 根据数据异质性和可容忍的恶意客户端比例,动态调节协作程度。

联邦学习(FL)允许多方在本地数据不共享的前提下协同训练模型,但因客户端数据分布差异,全局模型可能在部分客户端上表现不佳。个性化方法使每个客户端拥有适配自身数据的专属模型,同时仍能受益于其他客户端的数据。本文研究存在恶意客户端的联邦学习场景,推导出完全协作失败的条件。通过分析插值式个性化联邦学习框架在对抗性客户端下的泛化性能,精确刻画了完全协作劣于微调个性化的情形。研究确定了应根据数据异质性和可容忍的恶意客户端比例,适度降低协作强度。实验基于均值估计和二分类任务,在合成数据及基准图像分类数据集上验证了结论。

原文摘要 · Abstract (English)

Federated learning (FL) is an appealing paradigm that allows a group of machines (a.k.a. clients) to learn collectively while keeping their data local. However, due to the heterogeneity between the clients' data distributions, the model obtained through the use of FL algorithms may perform poorly on some client's data. Personalization addresses this issue by enabling each client to have a different model tailored to their own data while simultaneously benefiting from the other clients' data. We consider an FL setting where some clients can be adversarial, and we derive conditions under which full collaboration fails. Specifically, we analyze the generalization performance of an interpolated personalized FL framework in the presence of adversarial clients, and we precisely characterize situations when full collaboration performs strictly worse than fine-tuned personalization. Our analysis determines how much we should scale down the level of collaboration, according to data heterogeneity and the tolerable fraction of adversarial clients. We support our findings with empirical results on mean estimation and binary classification problems, considering synthetic and benchmark image classification datasets.

联邦学习个性化对抗性客户端

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。