arXiv:2505.09110cs.CRcs.DC2025-05被引 6

提出SafeFL算法,精准识别联邦学习中的恶意客户端。

Toward Malicious Clients Detection in Federated Learning

  • 通过生成合成数据集区分恶意与正常客户端模型行为
  • 在多个测试中检测准确率显著优于现有方法
  • 适合关注联邦学习安全性的研究人员和开发者

联邦学习(FL)允许多个客户端在不共享原始数据的情况下协同训练全局机器学习模型。然而,其去中心化特性易受投毒攻击威胁,恶意客户端可通过操纵本地模型干扰训练过程。尽管已有抗拜占庭聚合规则缓解此类攻击,但仍难以应对更高级威胁。近期研究聚焦于检测机制以识别潜在恶意参与者,但常误判大量良性客户端,或依赖服务器能力的不切实际假设。本文提出新型算法SafeFL,专为精准识别联邦学习中的恶意客户端设计。该方法由服务器收集一系列全局模型,生成合成数据集,基于模型行为差异区分恶意与良性模型。大量实验表明,SafeFL在检测准确率和效率上均优于现有方法。

原文摘要 · Abstract (English)

Federated learning (FL) enables multiple clients to collaboratively train a global machine learning model without sharing their raw data. However, the decentralized nature of FL introduces vulnerabilities, particularly to poisoning attacks, where malicious clients manipulate their local models to disrupt the training process. While Byzantine-robust aggregation rules have been developed to mitigate such attacks, they remain inadequate against more advanced threats. In response, recent advancements have focused on FL detection techniques to identify potentially malicious participants. Unfortunately, these methods often misclassify numerous benign clients as threats or rely on unrealistic assumptions about the server's capabilities. In this paper, we propose a novel algorithm, SafeFL, specifically designed to accurately identify malicious clients in FL. The SafeFL approach involves the server collecting a series of global models to generate a synthetic dataset, which is then used to distinguish between malicious and benign models based on their behavior. Extensive testing demonstrates that SafeFL outperforms existing methods, offering superior efficiency and accuracy in detecting malicious clients.

联邦学习安全检测恶意客户端模型行为分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。