通过多维度梯度分析与强化学习实现联邦学习的抗攻击鲁棒性
OptiGradTrust: Byzantine-Robust Federated Learning with Multi-Feature Gradient Analysis and Reinforcement Learning-Based Trust Weighting
- 用六维梯度指纹评估更新可信度,结合强化学习动态赋权
- 在非独立同分布数据下相比FLGuard提升1.6个百分点准确率
- 适合医疗等隐私敏感场景中存在恶意节点的联邦学习应用
联邦学习(FL)可在保护患者隐私的前提下,实现分布式医疗机构间的协同模型训练,但仍面临拜占庭攻击和统计异质性的挑战。我们提出OptiGradTrust,一个全面的防御框架,通过包含变分自编码器重构误差、余弦相似度、L2范数、符号一致性比率以及蒙特卡洛沙普利值的六维梯度指纹,评估梯度更新,并驱动混合强化学习-注意力模块进行自适应信任评分。为应对数据异质性带来的收敛难题,我们设计了FedBN-Prox(FedBN-P),融合联邦批量归一化与近端正则化,在准确率与收敛性间取得最优平衡。在MNIST、CIFAR-10及阿尔茨海默病MRI数据集上,针对多种拜占庭攻击场景的广泛评估表明,该方法显著优于现有先进防御方案,在非独立同分布条件下相比FLGuard最高提升1.6个百分点,且通过自适应学习策略对各类攻击模式保持稳健性能。
原文摘要 · Abstract (English)
Federated Learning (FL) enables collaborative model training across distributed medical institutions while preserving patient privacy, but remains vulnerable to Byzantine attacks and statistical heterogeneity. We present OptiGradTrust, a comprehensive defense framework that evaluates gradient updates through a novel six-dimensional fingerprint including VAE reconstruction error, cosine similarity metrics, $L_2$ norm, sign-consistency ratio, and Monte Carlo Shapley value, which drive a hybrid RL-attention module for adaptive trust scoring. To address convergence challenges under data heterogeneity, we develop FedBN-Prox (FedBN-P), combining Federated Batch Normalization with proximal regularization for optimal accuracy-convergence trade-offs. Extensive evaluation across MNIST, CIFAR-10, and Alzheimer's MRI datasets under various Byzantine attack scenarios demonstrates significant improvements over state-of-the-art defenses, achieving up to +1.6 percentage points over FLGuard under non-IID conditions while maintaining robust performance against diverse attack patterns through our adaptive learning approach.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。