arXiv:2502.08055cs.CRcs.LG2025-02

让客户端私有数据安全参与模型验证,提升联邦学习抗攻击能力

SLVR: Securely Leveraging Client Validation for Robust Federated Learning

  • 通过安全多方计算利用客户端私有数据做验证
  • 对抗自适应攻击时鲁棒性提升最高达50%
  • 无需公开验证数据,适合分布偏移场景

联邦学习(FL)可在保护客户端数据隐私的前提下实现协同建模,但暴露客户端更新易遭受重构攻击。安全聚合虽缓解隐私风险,却使服务器无法验证更新有效性,造成隐私与鲁棒性之间的权衡。现有方法多依赖零知识证明进行更新校验,但支持的验证条件有限且常需公开验证数据。本文提出SLVR框架,通过安全多方计算安全利用客户端私有数据,既无需公开验证数据,又可实现更广泛的鲁棒性检查,包括跨客户端准确率验证。该框架还能随客户端数据分布变化安全刷新验证数据。实验表明,SLVR在抵御模型投毒攻击方面显著提升,尤其在自适应攻击下性能优于现有方法高达50%;同时在多种分布偏移场景下仍保持良好适应性与稳定收敛。

原文摘要 · Abstract (English)

Federated Learning (FL) enables collaborative model training while keeping client data private. However, exposing individual client updates makes FL vulnerable to reconstruction attacks. Secure aggregation mitigates such privacy risks but prevents the server from verifying the validity of each client update, creating a privacy-robustness tradeoff. Recent efforts attempt to address this tradeoff by enforcing checks on client updates using zero-knowledge proofs, but they support limited predicates and often depend on public validation data. We propose SLVR, a general framework that securely leverages clients' private data through secure multi-party computation. By utilizing clients' data, SLVR not only eliminates the need for public validation data, but also enables a wider range of checks for robustness, including cross-client accuracy validation. It also adapts naturally to distribution shifts in client data as it can securely refresh its validation data up-to-date. Our empirical evaluations show that SLVR improves robustness against model poisoning attacks, particularly outperforming existing methods by up to 50% under adaptive attacks. Additionally, SLVR demonstrates effective adaptability and stable convergence under various distribution shift scenarios.

联邦学习隐私保护安全验证鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。