提出SafeSparse防御联邦学习中的梯度稀疏攻击,提升通信效率下的安全性。
Sparsification Under Siege: Dual-Level Defense Against Poisoning in Communication-Efficient Federated Learning
- 通过拓扑与语义双维度设计防御机制,解决稀疏化带来的安全漏洞。
- 在协同攻击下恢复25.7%的全局准确率,显著提升系统鲁棒性。
- 适合关注高效联邦学习安全性的研究人员与工业应用开发者。
梯度稀疏化虽缓解了联邦学习(FL)中的通信瓶颈,但从根本上改变了模型更新的几何结构。我们发现,由此产生的高维正交性使基于欧氏距离的鲁棒聚合度量在数学上变得模糊,形成‘稀疏性-鲁棒性权衡’,攻击者可借此绕过检测。为解决这一结构性矛盾,我们提出SafeSparse,一个共识恢复框架,将防御解耦为拓扑与语义两个维度。不同于以往将稀疏化与安全分离处理的方法,SafeSparse引入:(1) 基于杰卡德相似度的结构感知校准机制,过滤由索引投毒引发的拓扑异常点;(2) 利用更新符号密度聚类的方向语义对齐模块,中和幅度不变攻击。理论上,我们建立了SafeSparse的收敛保证。大量实验在多个数据集和攻击场景下验证,SafeSparse在协同投毒下仍能恢复最高达25.7%的全局准确率,有效填补了通信高效联邦学习中的安全漏洞。
原文摘要 · Abstract (English)
Gradient sparsification, while mitigating communication bottlenecks in Federated Learning (FL), fundamentally alters the geometric landscape of model updates. We reveal that the resultant high-dimensional orthogonality renders traditional Euclidean-based robust aggregation metrics mathematically ambiguous, creating a 'sparsity-robustness trade-off' that adversaries exploit to bypass detection. To resolve this structural dissonance, we propose SafeSparse, a consensus restoration framework that decouples defense into topological and semantic dimensions. Unlike prior arts that treat sparsification and security orthogonally, SafeSparse introduces: (1) a Structure-Aware Calibration mechanism utilizing Jaccard similarity to filter topological outliers induced by index poisoning; and (2) a Directional Semantic Alignment module employing density-based clustering on update signs to neutralize magnitude-invariant attacks. Theoretically, we establish convergence guarantees for SafeSparse. Extensive experiments across multiple datasets and attack scenarios demonstrate that SafeSparse recovers up to 25.7% global accuracy under coordinated poisoning, effectively closing the vulnerability gap in communication-efficient FL.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。