arXiv:2507.23638cs.LGcs.AI2025-07被引 3

通过多维度梯度分析与强化学习实现联邦学习的抗攻击鲁棒性

OptiGradTrust: Byzantine-Robust Federated Learning with Multi-Feature Gradient Analysis and Reinforcement Learning-Based Trust Weighting

  • 用六维梯度指纹评估更新可信度,结合强化学习动态赋权
  • 在非独立同分布数据下相比FLGuard提升1.6个百分点准确率
  • 适合医疗等隐私敏感场景中存在恶意节点的联邦学习应用

联邦学习(FL)可在保护患者隐私的前提下,实现分布式医疗机构间的协同模型训练,但仍面临拜占庭攻击和统计异质性的挑战。我们提出OptiGradTrust,一个全面的防御框架,通过包含变分自编码器重构误差、余弦相似度、L2范数、符号一致性比率以及蒙特卡洛沙普利值的六维梯度指纹,评估梯度更新,并驱动混合强化学习-注意力模块进行自适应信任评分。为应对数据异质性带来的收敛难题,我们设计了FedBN-Prox(FedBN-P),融合联邦批量归一化与近端正则化,在准确率与收敛性间取得最优平衡。在MNIST、CIFAR-10及阿尔茨海默病MRI数据集上,针对多种拜占庭攻击场景的广泛评估表明,该方法显著优于现有先进防御方案,在非独立同分布条件下相比FLGuard最高提升1.6个百分点,且通过自适应学习策略对各类攻击模式保持稳健性能。

原文摘要 · Abstract (English)

Federated Learning (FL) enables collaborative model training across distributed medical institutions while preserving patient privacy, but remains vulnerable to Byzantine attacks and statistical heterogeneity. We present OptiGradTrust, a comprehensive defense framework that evaluates gradient updates through a novel six-dimensional fingerprint including VAE reconstruction error, cosine similarity metrics, $L_2$ norm, sign-consistency ratio, and Monte Carlo Shapley value, which drive a hybrid RL-attention module for adaptive trust scoring. To address convergence challenges under data heterogeneity, we develop FedBN-Prox (FedBN-P), combining Federated Batch Normalization with proximal regularization for optimal accuracy-convergence trade-offs. Extensive evaluation across MNIST, CIFAR-10, and Alzheimer's MRI datasets under various Byzantine attack scenarios demonstrates significant improvements over state-of-the-art defenses, achieving up to +1.6 percentage points over FLGuard under non-IID conditions while maintaining robust performance against diverse attack patterns through our adaptive learning approach.

联邦学习拜占庭鲁棒医疗AI梯度分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。