提升边缘联邦学习抗模型扰动能力,让模型更稳定可靠。
Robust Federated Learning against Model Perturbation in Edge Networks
- 通过最小化参数邻域内的最大损失,寻找平坦的模型最低点。
- 在三种扰动场景下,对两个真实数据集的实验均显著优于基线方法。
- 适合关注边缘智能安全与鲁棒性的研究人员和工程师。
联邦学习(FL)是实现边缘智能的有前景范式,通过共享模型而非原始数据,使分布式边缘设备协同学习。然而,实际中共享模型常受各类扰动影响,导致性能显著下降。为此,本文提出一种新方法——基于尖锐度感知的鲁棒联邦学习(SMRFL),通过探索模型损失曲面的几何特性,增强模型对扰动的鲁棒性。SMRFL求解一个极小-极大优化问题,促使模型收敛至平坦最小值,从而降低对扰动的敏感性;因为在平坦最小值附近,模型参数扰动后仍保持低损失。理论分析表明,SMRFL的收敛速率与无扰动时的FL一致。大量实验结果表明,在两个真实数据集上,面对三种扰动场景,SMRFL相比三种基线方法显著提升了鲁棒性。
原文摘要 · Abstract (English)
Federated Learning (FL) is a promising paradigm for realizing edge intelligence, allowing collaborative learning among distributed edge devices by sharing models instead of raw data. However, the shared models are often assumed to be ideal, which would be inevitably violated in practice due to various perturbations, leading to significant performance degradation. To overcome this challenge, we propose a novel method, termed Sharpness-Aware Minimization-based Robust Federated Learning (SMRFL), which aims to improve model robustness against perturbations by exploring the geometrical property of the model landscape. Specifically, SMRFL solves a min-max optimization problem that promotes model convergence towards a flat minimum by minimizing the maximum loss within a neighborhood of the model parameters. In this way, model sensitivity to perturbations is reduced, and robustness is enhanced since models in the neighborhood of the flat minimum also enjoy low loss values. The theoretical result proves that SMRFL can converge at the same rate as FL without perturbations. Extensive experimental results show that SMRFL significantly enhances robustness against perturbations compared to three baseline methods on two real-world datasets under three perturbation scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。