提升边缘模型鲁棒性,应对数据异质与对抗攻击
Federated Hybrid Training and Self-Adversarial Distillation: Towards Robust Edge Networks
- 融合对抗训练与特征蒸馏,双路径增强模型鲁棒性
- 在多个数据集上保持高准确率的同时显著提升抗攻击能力
- 适合部署于数据隐私敏感的边缘计算场景
联邦学习(FL)是一种分布式训练技术,通过允许数据所有者在不传输原始数据的情况下协作,提升了移动边缘网络中的数据隐私。然而,数据异质性和对抗攻击给构建无偏且鲁棒的全局模型带来了挑战。为此,我们提出联邦混合对抗训练与自对抗蒸馏框架(FedBAT),旨在提升全局模型的鲁棒性与泛化能力。从数据增强角度,提出混合对抗训练,通过标准训练与对抗训练的加权组合,在准确率与鲁棒性间取得平衡。从特征蒸馏角度,引入一种增广不变的对抗蒸馏方法,将增强图像的局部对抗特征与其对应的全局无偏清洁特征对齐。该对齐机制能有效缓解数据异质性带来的偏差,同时增强模型的鲁棒性与泛化性能。在多个数据集上的大量实验表明,与多个基线相比,FedBAT在保持准确率的同时,显著提升了模型鲁棒性。
原文摘要 · Abstract (English)
Federated learning (FL) is a distributed training technology that enhances data privacy in mobile edge networks by allowing data owners to collaborate without transmitting raw data to the edge server. However, data heterogeneity and adversarial attacks pose challenges to develop an unbiased and robust global model for edge deployment. To address this, we propose Federated hyBrid Adversarial training and self-adversarial disTillation (FedBAT), a new framework designed to improve both robustness and generalization of the global model. FedBAT seamlessly integrates hybrid adversarial training and self-adversarial distillation into the conventional FL framework from data augmentation and feature distillation perspectives. From a data augmentation perspective, we propose hybrid adversarial training to defend against adversarial attacks by balancing accuracy and robustness through a weighted combination of standard and adversarial training. From a feature distillation perspective, we introduce a novel augmentation-invariant adversarial distillation method that aligns local adversarial features of augmented images with their corresponding unbiased global clean features. This alignment can effectively mitigate bias from data heterogeneity while enhancing both the robustness and generalization of the global model. Extensive experimental results across multiple datasets demonstrate that FedBAT yields comparable or superior performance gains in improving robustness while maintaining accuracy compared to several baselines.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。