arXiv:2502.17526cs.LGcs.CR2025-02被引 15

用博弈论方法识别恶意客户端,提升联邦学习抗攻击能力

FedSV: Byzantine-Robust Federated Learning via Shapley Value

  • 基于谢林值计算各客户端贡献度,动态评估其可靠性
  • 在跨孤岛场景下对多种攻击的防御成功率超90%
  • 适合关注联邦学习安全性的研究人员和工业应用开发者

联邦学习中,多个客户端协同训练模型:每个客户端维护本地模型与数据集,主服务器通过聚合客户端本地模型构建全局模型。然而,服务器与客户端间频繁通信易受攻击,可能破坏全局模型完整性,导致预测偏差。针对此类威胁,本文提出一种新型防御机制FedSV,利用谢林值(Shapley Value, SV)衡量客户端贡献——即某用户本地数据加入后对模型平均准确率的边际提升。该方法在学习过程中根据目标客户端所属分组,更稳健地估计其贡献。实验在跨孤岛设置下的MNIST数据集上验证了有效性,面对多种攻击,防御表现优异。

原文摘要 · Abstract (English)

In Federated Learning (FL), several clients jointly learn a machine learning model: each client maintains a local model for its local learning dataset, while a master server maintains a global model by aggregating the local models of the client devices. However, the repetitive communication between server and clients leaves room for attacks aimed at compromising the integrity of the global model, causing errors in its targeted predictions. In response to such threats on FL, various defense measures have been proposed in the literature. In this paper, we present a powerful defense against malicious clients in FL, called FedSV, using the Shapley Value (SV), which has been proposed recently to measure user contribution in FL by computing the marginal increase of average accuracy of the model due to the addition of local data of a user. Our approach makes the identification of malicious clients more robust, since during the learning phase, it estimates the contribution of each client according to the different groups to which the target client belongs. FedSV's effectiveness is demonstrated by extensive experiments on MNIST datasets in a cross-silo context under various attacks.

联邦学习安全防御博弈论恶意客户端

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。