arXiv:2506.09674cs.LG2025-06被引 1

用小波与傅里叶变换提前识别联邦学习中的恶意客户端

Wavelet Scattering Transform and Fourier Representation for Offline Detection of Malicious Clients in Federated Learning

  • 用小波散射或傅里叶变换生成客户端压缩特征
  • 检测准确率优于现有方法,提升下游分类性能
  • 无需原始数据,适合隐私敏感的联邦学习场景

联邦学习(FL)可在保护数据隐私的前提下跨去中心化客户端训练模型,但异常或受损客户端(如故障传感器或非代表性数据分布)会显著降低模型性能。在不访问原始数据的前提下检测此类客户端仍是关键挑战。本文提出WAFFLE(Wavelet and Fourier representations for Federated Learning),一种在训练前标记恶意客户端的算法,利用本地计算的压缩表示——基于小波散射变换(WST)或傅里叶变换——生成低维、任务无关的嵌入,适用于无监督客户端分离。一个轻量级检测器在蒸馏后的公共数据集上训练,实现极低通信与计算开销。尽管两种变换均有效,小波散射因具备不可逆性和对局部形变的稳定性,在联邦场景中更具理论优势。在基准数据集上的实验表明,该方法在检测准确率和下游分类性能上均优于现有联邦学习异常检测算法,验证其作为在线检测策略替代方案的有效性。

原文摘要 · Abstract (English)

Federated Learning (FL) enables the training of machine learning models across decentralized clients while preserving data privacy. However, the presence of anomalous or corrupted clients - such as those with faulty sensors or non representative data distributions - can significantly degrade model performance. Detecting such clients without accessing raw data remains a key challenge. We propose WAFFLE (Wavelet and Fourier representations for Federated Learning) a detection algorithm that labels malicious clients {\it before training}, using locally computed compressed representations derived from either the Wavelet Scattering Transform (WST) or the Fourier Transform. Both approaches provide low-dimensional, task-agnostic embeddings suitable for unsupervised client separation. A lightweight detector, trained on a distillated public dataset, performs the labeling with minimal communication and computational overhead. While both transforms enable effective detection, WST offers theoretical advantages, such as non-invertibility and stability to local deformations, that make it particularly well-suited to federated scenarios. Experiments on benchmark datasets show that our method improves detection accuracy and downstream classification performance compared to existing FL anomaly detection algorithms, validating its effectiveness as a pre-training alternative to online detection strategies.

联邦学习异常检测小波变换隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。