提出新型防御机制,让联邦学习在多种攻击下仍能稳定训练。
Defending Against Diverse Attacks in Federated Learning Through Consensus-Based Bi-Level Optimization
- 用双层优化建模联邦学习,通过共识机制增强抗干扰能力。
- 理论证明算法在恶意节点存在时仍能收敛,实验证明抗标签翻转攻击有效。
- 适用于实际分布式场景,适合关注模型安全的开发者和研究者。
对抗性攻击对机器学习应用构成重大挑战,尤其在分布式训练和联邦学习中,恶意参与者可能破坏训练过程,损害最终模型的性能与可靠性。本文将训练任务建模为双层优化问题,提出基于共识的双层优化(CB²O)方法,并对其在对抗环境下的鲁棒性进行理论分析。具体地,在均场定律下证明了CB²O在存在恶意节点时的全局收敛性,展示了其对多样化攻击的鲁棒性;同时揭示了特定超参数选择对缓解攻击效果的关键作用。在实践层面,进一步将CB²O拓展至分簇联邦学习场景,提出新型多粒子系统FedCB²O,并设计出适用于真实应用的实用算法。大量实验表明,该算法在去中心化分簇联邦学习中对标签翻转攻击具有显著防御能力,验证了其在实际场景中的有效性。
原文摘要 · Abstract (English)
Adversarial attacks pose significant challenges in many machine learning applications, particularly in the setting of distributed training and federated learning, where malicious agents seek to corrupt the training process with the goal of jeopardizing and compromising the performance and reliability of the final models. In this paper, we address the problem of robust federated learning in the presence of such attacks by formulating the training task as a bi-level optimization problem. We conduct a theoretical analysis of the resilience of consensus-based bi-level optimization (CB$^2$O), an interacting multi-particle metaheuristic optimization method, in adversarial settings. Specifically, we provide a global convergence analysis of CB$^2$O in mean-field law in the presence of malicious agents, demonstrating the robustness of CB$^2$O against a diverse range of attacks. Thereby, we offer insights into how specific hyperparameter choices enable to mitigate adversarial effects. On the practical side, we extend CB$^2$O to the clustered federated learning setting by proposing FedCB$^2$O, a novel interacting multi-particle system, and design a practical algorithm that addresses the demands of real-world applications. Extensive experiments demonstrate the robustness of the FedCB$^2$O algorithm against label-flipping attacks in decentralized clustered federated learning scenarios, showcasing its effectiveness in practical contexts.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。