arXiv:2503.10792cs.LGcs.AI2025-03被引 5

用分布式优化提升联邦学习抗恶意攻击能力,比传统方法更稳定高效。

Byzantine-Resilient Federated Learning via Distributed Optimization

  • 采用增广拉格朗日法实现分布式优化,通过共识机制天然抵抗恶意干扰。
  • 在多个数据集上测试,相比传统方法准确率更高、收敛更快、稳定性更强。
  • 适合关注联邦学习安全性的研究者和工业界部署者参考。

拜占庭攻击对联邦学习构成严峻挑战,恶意参与者可破坏训练过程、降低模型精度并威胁系统可靠性。传统联邦学习依赖聚合式更新协议,易受复杂攻击策略影响。本文证明,分布式优化为聚合中心方法提供了原则性且鲁棒的替代方案。具体而言,增广拉格朗日乘子法(PDMM)通过其容错共识机制,天然抑制拜占庭攻击的影响。我们在三个数据集(MNIST、FashionMNIST、Olivetti)上进行了大量实验,涵盖比特翻转与高斯噪声注入等多种攻击场景,验证了分布式优化协议的优越鲁棒性。相较于传统聚合方法,PDMM在模型效用、收敛速度和稳定性方面均表现更优。结果表明,分布式优化在防御拜占庭威胁方面极具有效性,为构建更安全、可靠的联邦学习系统开辟了新路径。

原文摘要 · Abstract (English)

Byzantine attacks present a critical challenge to Federated Learning (FL), where malicious participants can disrupt the training process, degrade model accuracy, and compromise system reliability. Traditional FL frameworks typically rely on aggregation-based protocols for model updates, leaving them vulnerable to sophisticated adversarial strategies. In this paper, we demonstrate that distributed optimization offers a principled and robust alternative to aggregation-centric methods. Specifically, we show that the Primal-Dual Method of Multipliers (PDMM) inherently mitigates Byzantine impacts by leveraging its fault-tolerant consensus mechanism. Through extensive experiments on three datasets (MNIST, FashionMNIST, and Olivetti), under various attack scenarios including bit-flipping and Gaussian noise injection, we validate the superior resilience of distributed optimization protocols. Compared to traditional aggregation-centric approaches, PDMM achieves higher model utility, faster convergence, and improved stability. Our results highlight the effectiveness of distributed optimization in defending against Byzantine threats, paving the way for more secure and resilient federated learning systems.

联邦学习拜占庭攻击分布式优化安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。