arXiv:2412.07454cs.LGcs.AI2024-12被引 3

通过参数乱序提升联邦学习安全与隐私,防御攻击且不降性能。

Tazza: Shuffling Neural Network Parameters for Secure and Private Federated Learning

  • 用权重乱序和打乱验证增强模型对投毒攻击的抗性。
  • 在多个数据集上实现最高6.7倍计算效率提升,性能无损。
  • 适合注重安全与效率的边缘设备联邦学习场景。

联邦学习可在不共享原始数据的情况下实现分布式模型训练,保护数据隐私。然而,其仍面临梯度反演和恶意客户端模型投毒等关键安全威胁,现有方案常分别应对这些问题,导致系统鲁棒性或模型准确率受损。本文提出 Tazza,一种安全高效的联邦学习框架,同时解决上述挑战。通过利用神经网络的权重置换等变性与不变性特性,结合参数乱序与打乱模型验证,Tazza 增强了对多种投毒攻击的防御能力,同时保障数据机密性和高模型精度。在多个数据集及嵌入式平台上的全面评估表明,Tazza 在保持性能的前提下,相较其他方案计算效率最高提升6.7倍。

原文摘要 · Abstract (English)

Federated learning enables decentralized model training without sharing raw data, preserving data privacy. However, its vulnerability towards critical security threats, such as gradient inversion and model poisoning by malicious clients, remain unresolved. Existing solutions often address these issues separately, sacrificing either system robustness or model accuracy. This work introduces Tazza, a secure and efficient federated learning framework that simultaneously addresses both challenges. By leveraging the permutation equivariance and invariance properties of neural networks via weight shuffling and shuffled model validation, Tazza enhances resilience against diverse poisoning attacks, while ensuring data confidentiality and high model accuracy. Comprehensive evaluations on various datasets and embedded platforms show that Tazza achieves robust defense with up to 6.7x improved computational efficiency compared to alternative schemes, without compromising performance.

联邦学习安全防护参数扰动边缘计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。