arXiv:2505.02490cs.LGstat.ML2025-05被引 1

用贝叶斯方法自适应聚合模型更新,抗恶意客户端攻击

Bayesian Robust Aggregation for Federated Learning

  • 基于贝叶斯推断动态判断每客户端诚实概率,自动调整聚合权重
  • 在三个图像分类数据集上,对抗静态与动态恶意客户端均达最优性能
  • 无需预知恶意客户端数量,兼具简洁性与强鲁棒性,适合真实场景

联邦学习允许多方在分布式数据上协作训练模型,但易受部分客户端提交污染模型更新的攻击。现实中被攻陷客户端数量通常未知,且攻击强度可能随时间变化。为此,我们提出一种基于贝叶斯推断的自适应鲁棒聚合方法:通过最大化对每个客户端为‘诚实’的概率进行边缘化后的似然函数,定义平均更新。该方法兼具经典平均估计器(如样本均值或几何中位数)的简洁性,且不依赖恶意客户端数量;同时在抵御攻击方面表现与专为联邦学习设计的方法(如Krum)相当。我们在三个基准图像分类数据集上对比了多种聚合方案,所提方法在各类攻击下,无论恶意客户端数量固定或变动,均持续取得领先性能。

原文摘要 · Abstract (English)

Federated Learning enables collaborative training of machine learning models on decentralized data. This scheme, however, is vulnerable to adversarial attacks, when some of the clients submit corrupted model updates. In real-world scenarios, the total number of compromised clients is typically unknown, with the extent of attacks potentially varying over time. To address these challenges, we propose an adaptive approach for robust aggregation of model updates based on Bayesian inference. The mean update is defined by the maximum of the likelihood marginalized over probabilities of each client to be `honest'. As a result, the method shares the simplicity of the classical average estimators (e.g., sample mean or geometric median), being independent of the number of compromised clients. At the same time, it is as effective against attacks as methods specifically tailored to Federated Learning, such as Krum. We compare our approach with other aggregation schemes in federated setting on three benchmark image classification data sets. The proposed method consistently achieves state-of-the-art performance across various attack types with static and varying number of malicious clients.

联邦学习鲁棒聚合贝叶斯方法安全训练

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。