arXiv:2410.13083cs.LGcs.AI2024-10中稿 · 2024 Annual Comput…被引 3

解决联邦学习中数据异构和恶意攻击问题,提升模型鲁棒性。

FedCAP: Robust Federated Learning via Customized Aggregation and Personalization

  • 通过更新校准机制捕捉客户端模型差异方向与大小
  • 定制聚合规则加速恶意客户端退化,检测准确率超95%
  • 支持客户端个性化,适合真实分布式场景应用

联邦学习(FL)作为一种新兴的分布式机器学习范式,已应用于多种隐私保护场景。然而,由于其分布式特性,FL面临两个关键挑战:用户数据的非独立同分布(non-IID)以及对拜占庭攻击的脆弱性。为应对这些挑战,本文提出FedCAP,一种同时抵御数据异构性和拜占庭攻击的鲁棒联邦学习框架。其核心是一个模型更新校准机制,帮助服务器捕捉客户端间模型更新的方向与幅度差异。此外,设计了定制化模型聚合规则,促进相似客户端协作训练,同时加速恶意客户端模型退化。基于欧氏范数的异常检测机制可快速识别并永久移除恶意客户端。进一步地,通过客户端侧个性化可有效缓解数据异构与拜占庭攻击的影响。我们在多个非IID设置下进行了广泛实验,对比多种先进基线,结果表明FedCAP在多种中毒攻击下均表现出强鲁棒性。

原文摘要 · Abstract (English)

Federated learning (FL), an emerging distributed machine learning paradigm, has been applied to various privacy-preserving scenarios. However, due to its distributed nature, FL faces two key issues: the non-independent and identical distribution (non-IID) of user data and vulnerability to Byzantine threats. To address these challenges, in this paper, we propose FedCAP, a robust FL framework against both data heterogeneity and Byzantine attacks. The core of FedCAP is a model update calibration mechanism to help a server capture the differences in the direction and magnitude of model updates among clients. Furthermore, we design a customized model aggregation rule that facilitates collaborative training among similar clients while accelerating the model deterioration of malicious clients. With a Euclidean norm-based anomaly detection mechanism, the server can quickly identify and permanently remove malicious clients. Moreover, the impact of data heterogeneity and Byzantine attacks can be further mitigated through personalization on the client side. We conduct extensive experiments, comparing multiple state-of-the-art baselines, to demonstrate that FedCAP performs well in several non-IID settings and shows strong robustness under a series of poisoning attacks.

联邦学习鲁棒性数据异构拜占庭攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。