arXiv:2502.00587cs.CRcs.AI2025-02被引 10

提出鲁棒知识蒸馏机制,防御联邦学习中的后门攻击

Robust Knowledge Distillation in Federated Learning: Counteracting Backdoor Attacks

  • 通过聚类与模型筛选识别恶意更新,构建可信模型集合
  • 利用知识蒸馏将集合共识迁移至全局模型,有效抵御后门攻击
  • 无需苛刻假设,适用于多样数据分布与高比例恶意客户端

联邦学习(FL)可在保护数据隐私的前提下实现跨设备协同训练,但易受后门攻击威胁,即恶意参与者可能破坏全局模型。现有防御方法受限于对数据异质性(非独立同分布数据)和恶意客户端比例的严格假设,实用性与有效性不足。为此,我们提出鲁棒知识蒸馏(RKD),一种不依赖苛刻假设的新防御机制。RKD结合聚类与模型选择技术,识别并过滤恶意更新,形成可靠的模型集成;再通过知识蒸馏将该集成的集体知识迁移至全局模型。大量实验表明,RKD在多种场景下均能有效缓解后门威胁,同时保持高模型性能,优于当前主流防御方法。

原文摘要 · Abstract (English)

Federated Learning (FL) enables collaborative model training across multiple devices while preserving data privacy. However, it remains susceptible to backdoor attacks, where malicious participants can compromise the global model. Existing defence methods are limited by strict assumptions on data heterogeneity (Non-Independent and Identically Distributed data) and the proportion of malicious clients, reducing their practicality and effectiveness. To overcome these limitations, we propose Robust Knowledge Distillation (RKD), a novel defence mechanism that enhances model integrity without relying on restrictive assumptions. RKD integrates clustering and model selection techniques to identify and filter out malicious updates, forming a reliable ensemble of models. It then employs knowledge distillation to transfer the collective insights from this ensemble to a global model. Extensive evaluations demonstrate that RKD effectively mitigates backdoor threats while maintaining high model performance, outperforming current state-of-the-art defence methods across various scenarios.

联邦学习后门攻击知识蒸馏安全防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。