arXiv:2507.14322cs.LGcs.CR2025-07被引 4

用自适应策略动态选择最佳防御方法,提升联邦学习抗攻击能力。

FedStrategist: A Meta-Learning Framework for Adaptive and Robust Aggregation in Federated Learning

  • 设计轻量级上下文赌博代理,根据实时诊断指标选最优聚合规则。
  • 在多种场景下超越单一静态防御,对隐蔽攻击也有效,准确率更高。
  • 可通过风险参数调控安全与性能平衡,适合实际部署的系统设计。

联邦学习(FL)提供了隐私保护的协作人工智能范式,但其去中心化特性使其易受模型投毒攻击。尽管已有多种静态防御机制,但其效果高度依赖环境,常在异构数据或自适应攻击下失效。本文提出FedStrategist,一种将鲁棒聚合重构为实时、成本敏感控制问题的元学习框架。设计一个轻量级上下文赌博代理,基于实时诊断指标从防御规则库中动态选择最优聚合策略。实验表明,单一静态规则无普适最优性;所提代理在多样场景中均能学习出更优策略,包括有利于Krum的环境及针对特定诊断信号设计的“隐蔽”攻击者。特别地,分析了非鲁棒基线虽高准确率但结果被污染的悖论,并证明代理能学习保守策略以优先保障模型完整性。进一步证明,代理策略可通过单个“风险容忍度”参数可控,使从业者显式管理性能与安全的权衡。本工作为构建弹性、智能的分布式人工智能系统提供新思路。

原文摘要 · Abstract (English)

Federated Learning (FL) offers a paradigm for privacy-preserving collaborative AI, but its decentralized nature creates significant vulnerabilities to model poisoning attacks. While numerous static defenses exist, their effectiveness is highly context-dependent, often failing against adaptive adversaries or in heterogeneous data environments. This paper introduces FedStrategist, a novel meta-learning framework that reframes robust aggregation as a real-time, cost-aware control problem. We design a lightweight contextual bandit agent that dynamically selects the optimal aggregation rule from an arsenal of defenses based on real-time diagnostic metrics. Through comprehensive experiments, we demonstrate that no single static rule is universally optimal. We show that our adaptive agent successfully learns superior policies across diverse scenarios, including a ``Krum-favorable" environment and against a sophisticated "stealth" adversary designed to neutralize specific diagnostic signals. Critically, we analyze the paradoxical scenario where a non-robust baseline achieves high but compromised accuracy, and demonstrate that our agent learns a conservative policy to prioritize model integrity. Furthermore, we prove the agent's policy is controllable via a single "risk tolerance" parameter, allowing practitioners to explicitly manage the trade-off between performance and security. Our work provides a new, practical, and analyzable approach to creating resilient and intelligent decentralized AI systems.

联邦学习元学习安全防御自适应聚合

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。