arXiv:2506.20413cs.LGcs.AI2025-06中稿 · publication at the…

P4让物联网设备在隐私保护下协同训练,抗恶意攻击且效率高。

Client Clustering Meets Knowledge Sharing: Enhancing Privacy and Robustness in Personalized Peer-to-Peer Learning

  • 基于差分隐私的轻量级聚类,自动分组协作训练。
  • 相比现有方法准确率提升5%~30%,可抵抗30%恶意客户端。
  • 适用于资源受限设备,两设备协作仅增7秒延迟。

人工智能在物联网生态中的普及,推动了在异构、资源受限设备上高效且私密的个性化学习需求。然而,去中心化环境下的个性化学习面临知识传递效率低、数据隐私保护难、抗投毒攻击能力弱等挑战。本文提出P4(Personalized, Private, Peer-to-Peer)方法,旨在为资源受限的物联网设备提供个性化模型,同时保障差分隐私并具备抗投毒攻击能力。P4采用轻量级全去中心化算法,私密检测客户端相似性并形成协作组;组内通过差分隐私知识蒸馏协同训练模型,在保持高精度的同时抵御恶意客户端干扰。我们在多个基准数据集上,使用线性与CNN架构在不同异构性和攻击场景下评估P4。实验表明,相较于领先的差分隐私对等学习方法,P4准确率提升5%至30%,且能容忍高达30%的恶意客户端。此外,我们在资源受限设备上部署验证,两个客户端协作训练仅增加约7秒开销。

原文摘要 · Abstract (English)

The growing adoption of Artificial Intelligence (AI) in Internet of Things (IoT) ecosystems has intensified the need for personalized learning methods that can operate efficiently and privately across heterogeneous, resource-constrained devices. However, enabling effective personalized learning in decentralized settings introduces several challenges, including efficient knowledge transfer between clients, protection of data privacy, and resilience against poisoning attacks. In this paper, we address these challenges by developing P4 (Personalized, Private, Peer-to-Peer) -- a method designed to deliver personalized models for resource-constrained IoT devices while ensuring differential privacy and robustness against poisoning attacks. Our solution employs a lightweight, fully decentralized algorithm to privately detect client similarity and form collaborative groups. Within each group, clients leverage differentially private knowledge distillation to co-train their models, maintaining high accuracy while ensuring robustness to the presence of malicious clients. We evaluate P4 on popular benchmark datasets using both linear and CNN-based architectures across various heterogeneity settings and attack scenarios. Experimental results show that P4 achieves 5% to 30% higher accuracy than leading differentially private peer-to-peer approaches and maintains robustness with up to 30% malicious clients. Additionally, we demonstrate its practicality by deploying it on resource-constrained devices, where collaborative training between two clients adds only ~7 seconds of overhead.

联邦学习差分隐私物联网对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。