arXiv:2412.12324cs.CRcs.LG2024-12被引 20

用联邦学习实现隐私保护的风险认证,提升安全与用户体验。

F-RBA: A Federated Learning-based Framework for Risk-based Authentication

  • 用户数据本地训练,通过联邦学习分布式评估风险
  • 真实数据集测试显示可疑登录检测真阳性率更高
  • 适合注重隐私的分布式系统和新用户快速适配场景

互联网服务普及带来隐私保护需求激增。用户认证是保障数据安全的关键机制,但传统方式仍易受凭证泄露、设备被盗、会话劫持等问题影响,且缺乏自适应安全措施。风险基础认证(RBA)提供多层级认证方案,在不降低安全性的前提下优化用户体验。本文提出基于联邦学习的联邦风险认证(F-RBA)框架,通过本地化训练保护用户数据,实现设备端分布式风险评估。其核心创新在于基于相似性的特征工程,解决联邦设置中的数据异构问题。该框架支持跨设备实时风险评估并维护统一用户画像,在数据保护、安全性和可扩展性间取得平衡。通过联邦学习缓解冷启动问题,使新用户能快速建立风险模型。基于真实多用户数据集的实证评估表明,该框架在检测可疑登录方面优于传统无监督异常检测模型,展现出更高的真阳性率。本研究为分布式数字环境下的隐私导向风险认证提供了新范式,推动联邦安全系统的进步。

原文摘要 · Abstract (English)

The proliferation of Internet services has led to an increasing need to protect private data. User authentication serves as a crucial mechanism to ensure data security. Although robust authentication forms the cornerstone of remote service security, it can still leave users vulnerable to credential disclosure, device-theft attacks, session hijacking, and inadequate adaptive security measures. Risk-based Authentication (RBA) emerges as a potential solution, offering a multi-level authentication approach that enhances user experience without compromising security. In this paper, we propose a Federated Risk-based Authentication (F-RBA) framework that leverages Federated Learning to ensure privacy-centric training, keeping user data local while distributing learning across devices. Whereas traditional approaches rely on centralized storage, F-RBA introduces a distributed architecture where risk assessment occurs locally on users' devices. The framework's core innovation lies in its similarity-based feature engineering approach, which addresses the heterogeneous data challenges inherent in federated settings, a significant advancement for distributed authentication. By facilitating real-time risk evaluation across devices while maintaining unified user profiles, F-RBA achieves a balance between data protection, security, and scalability. Through its federated approach, F-RBA addresses the cold-start challenge in risk model creation, enabling swift adaptation to new users without compromising security. Empirical evaluation using a real-world multi-user dataset demonstrates the framework's effectiveness, achieving a superior true positive rate for detecting suspicious logins compared to conventional unsupervised anomaly detection models. This research introduces a new paradigm for privacy-focused RBA in distributed digital environments, facilitating advancements in federated security systems.

联邦学习风险认证隐私保护安全系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。