提出动态可解释的防御机制,提升联邦学习中差质客户端的公平性与抗攻击能力。
RAB$^2$-DEF: Dynamic and explainable defense against adversarial attacks in Federated Learning to fair poor clients
- 基于本地线性解释实现动态可解释防御
- 在图像数据集上有效抵御拜占庭与后门攻击,性能优于现有方法
- 特别关注差质客户端公平性,推动可信AI发展
随着人工智能普及,数据隐私监管需求日益增长。联邦学习因其分布式特性被视为解决多源数据隐私问题的有效方案。现有防御机制仅关注对抗攻击防护与性能,忽视可解释性、对差质客户端的公平性、攻击配置的动态适应性以及对多种攻击的泛化鲁棒性。本文提出RAB²-DEF,一种针对拜占庭和后门攻击的鲁棒、动态、可解释且公平对待差质客户端的防御方法,采用本地线性解释实现可解释性。在图像数据集上,通过对比最先进的防御方法,在同时应对拜占庭与后门攻击时,RAB²-DEF表现出优异的防御性能,显著提升了可信人工智能所需的关键品质。
原文摘要 · Abstract (English)
At the same time that artificial intelligence is becoming popular, concern and the need for regulation is growing, including among other requirements the data privacy. In this context, Federated Learning is proposed as a solution to data privacy concerns derived from different source data scenarios due to its distributed learning. The defense mechanisms proposed in literature are just focused on defending against adversarial attacks and the performance, leaving aside other important qualities such as explainability, fairness to poor quality clients, dynamism in terms of attacks configuration and generality in terms of being resilient against different kinds of attacks. In this work, we propose RAB$^2$-DEF, a $\textbf{r}$esilient $\textbf{a}$gainst $\textbf{b}\text{yzantine}$ and $\textbf{b}$ackdoor attacks which is $\textbf{d}$ynamic, $\textbf{e}$xplainable and $\textbf{f}$air to poor clients using local linear explanations. We test the performance of RAB$^2$-DEF in image datasets and both byzantine and backdoor attacks considering the state-of-the-art defenses and achieve that RAB$^2$-DEF is a proper defense at the same time that it boosts the other qualities towards trustworthy artificial intelligence.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。