SNN在联邦学习中抗非全知攻击,压缩通信量同时提升鲁棒性。
The Robustness of Spiking Neural Networks in Federated Learning with Compression Against Non-omniscient Byzantine Attacks
- 将Top-κ稀疏化融入联邦学习,降低通信开销。
- 面对非全知攻击,SNN模型准确率提升约40%。
- 适合资源受限的物联网设备安全训练场景。
脉冲神经网络(SNN)因其出色的推理能效,联邦学习(FL)因支持隐私保护的分布式训练,正成为物联网(IoT)设备的重要研究方向。然而,针对联邦学习中的拜占庭攻击与带宽限制问题,尤其是对FL-SNN的影响,现有研究仍较匮乏。本文揭示了在非全知拜占庭攻击(攻击者无法访问本地客户端数据)下,FL-SNN相较于传统人工神经网络(FL-ANN)具有双重优势:更强的鲁棒性与更高的通信效率。具体而言,仅通过在联邦框架中引入简单的Top-κ稀疏化,即可显著降低通信量,并大幅增强对抗非全知攻击的稳定性。最显著的是,在致命的Min-Max攻击下,FL-SNN训练的准确率提升了约40%。
原文摘要 · Abstract (English)
Spiking Neural Networks (SNNs), which offer exceptional energy efficiency for inference, and Federated Learning (FL), which offers privacy-preserving distributed training, is a rising area of interest that highly beneficial towards Internet of Things (IoT) devices. Despite this, research that tackles Byzantine attacks and bandwidth limitation in FL-SNNs, both poses significant threats on model convergence and training times, still remains largely unexplored. Going beyond proposing a solution for both of these problems, in this work we highlight the dual benefits of FL-SNNs, against non-omniscient Byzantine adversaries (ones that restrict attackers access to local clients datasets), and greater communication efficiency, over FL-ANNs. Specifically, we discovered that a simple integration of Top-\k{appa} sparsification into the FL apparatus can help leverage the advantages of the SNN models in both greatly reducing bandwidth usage and significantly boosting the robustness of FL training against non-omniscient Byzantine adversaries. Most notably, we saw a massive improvement of roughly 40% accuracy gain in FL-SNNs training under the lethal MinMax attack
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。