arXiv:2506.16723cs.LGcs.AI2025-06

提出三重混淆与贡献感知框架,提升医疗联邦学习隐私与鲁棒性。

TriCon-SF: A Triple-Shuffle and Contribution-Aware Serial Federated Learning Framework for Heterogeneous Healthcare Data

  • 通过层、数据段、训练序列三重随机化,破坏学习模式
  • 用Shapley值动态评估贡献,检测恶意客户端
  • 在医疗数据上兼顾精度与通信效率,适合敏感场景

串行管道训练是处理跨孤岛联邦学习中数据异构性的高效范式,通信开销低。然而,即使无中心聚合,客户端间直接传递模型仍可能违反隐私法规,易受梯度泄露和关联攻击影响。此外,在医疗等高隐私敏感领域,防范半诚实或恶意客户端篡改或滥用接收模型仍是重大挑战。为此,我们提出TriCon-SF,一种集成三重混淆与贡献感知的新型串行联邦学习框架。该框架通过随机打乱模型层、数据片段和训练顺序,实现三个层级的随机化,打破确定性学习模式,阻断潜在攻击路径,增强隐私与鲁棒性。同时,采用Shapley值方法动态评估训练期间各客户端贡献,支持异常行为检测与系统可问责性。在非独立同分布(non-IID)医疗数据集上的大量实验表明,TriCon-SF在准确率和通信效率上均优于标准串行与并行联邦学习。安全性分析进一步验证其对客户端侧隐私攻击的抵御能力。

原文摘要 · Abstract (English)

Serial pipeline training is an efficient paradigm for handling data heterogeneity in cross-silo federated learning with low communication overhead. However, even without centralized aggregation, direct transfer of models between clients can violate privacy regulations and remain susceptible to gradient leakage and linkage attacks. Additionally, ensuring resilience against semi-honest or malicious clients who may manipulate or misuse received models remains a grand challenge, particularly in privacy-sensitive domains such as healthcare. To address these challenges, we propose TriCon-SF, a novel serial federated learning framework that integrates triple shuffling and contribution awareness. TriCon-SF introduces three levels of randomization by shuffling model layers, data segments, and training sequences to break deterministic learning patterns and disrupt potential attack vectors, thereby enhancing privacy and robustness. In parallel, it leverages Shapley value methods to dynamically evaluate client contributions during training, enabling the detection of dishonest behavior and enhancing system accountability. Extensive experiments on non-IID healthcare datasets demonstrate that TriCon-SF outperforms standard serial and parallel federated learning in both accuracy and communication efficiency. Security analysis further supports its resilience against client-side privacy attacks.

联邦学习医疗AI隐私保护安全建模

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。