arXiv:2503.03684cs.LGcs.CR2025-03

提出三位一体框架,提升联邦学习的抗攻击、公平性与隐私保护能力。

Towards Trustworthy Federated Learning

  • 采用双向范数筛选机制,剔除异常梯度,抵御恶意节点攻击。
  • 在真实数据集上同时提升系统鲁棒性与公平性,且隐私与精度平衡良好。
  • 首个理论与实验结合验证三重可信性的联邦学习研究,适合安全敏感场景。

本文构建了一个综合性框架,解决联邦学习中的三大可信挑战:对拜占庭攻击的鲁棒性、公平性以及隐私保护。为应对恶意节点发送误导性信息的问题,提出双侧范数筛选(TNBS)机制,由中心服务器剔除梯度范数最低和最高的部分,实现对异常参与者的过滤。为促进公平性,采用 q-公平联邦学习(q-FFL)。同时引入基于差分隐私的方案,防止本地原始数据被推断。在不同场景下提供了收敛性保证。实验证明该框架在真实数据集上有效提升了鲁棒性与公平性,同时在隐私与精度之间取得良好权衡。本工作是首个在理论上与实验中同时涵盖公平性、隐私与鲁棒性的可信联邦学习研究。

原文摘要 · Abstract (English)

This paper develops a comprehensive framework to address three critical trustworthy challenges in federated learning (FL): robustness against Byzantine attacks, fairness, and privacy preservation. To improve the system's defense against Byzantine attacks that send malicious information to bias the system's performance, we develop a Two-sided Norm Based Screening (TNBS) mechanism, which allows the central server to crop the gradients that have the l lowest norms and h highest norms. TNBS functions as a screening tool to filter out potential malicious participants whose gradients are far from the honest ones. To promote egalitarian fairness, we adopt the q-fair federated learning (q-FFL). Furthermore, we adopt a differential privacy-based scheme to prevent raw data at local clients from being inferred by curious parties. Convergence guarantees are provided for the proposed framework under different scenarios. Experimental results on real datasets demonstrate that the proposed framework effectively improves robustness and fairness while managing the trade-off between privacy and accuracy. This work appears to be the first study that experimentally and theoretically addresses fairness, privacy, and robustness in trustworthy FL.

联邦学习隐私保护鲁棒性公平性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。