综述联邦学习的攻防技术与未来方向,助你快速掌握安全隐私要点。
On the Security and Privacy of Federated Learning: A Survey with Attacks, Defenses, Frameworks, Applications, and Future Directions
- 梳理200+篇论文,分类整理安全增强与隐私保护方法
- 揭示隐私、安全与模型性能间的权衡关系,分析非独立同分布数据影响
- 适合研究者与工程师参考,指导构建更鲁棒的联邦学习系统
联邦学习(FL)是一种新兴的分布式机器学习范式,允许多个客户端在不共享原始数据的情况下协同训练全局模型。尽管FL设计上增强了数据隐私,但仍面临多种安全与隐私威胁。本文综述了超过200篇关于最新攻击与防御机制的研究,将其分为安全增强和隐私保护两类。安全增强方法旨在提升对恶意行为(如拜占庭攻击、投毒攻击、Sybil攻击)的鲁棒性;隐私保护技术则通过密码学、差分隐私和安全聚合等手段保护敏感数据。我们批判性分析现有方法的优势与局限,强调隐私、安全与模型性能之间的权衡,并讨论非独立同分布(non-IID)数据对防御效果的影响。此外,本文识别出开放研究挑战与未来方向,包括在动态异构环境中实现可扩展、自适应、低能耗的解决方案。本综述旨在为研究人员和从业者提供指导,推动构建更安全、隐私友好的协同学习系统。
原文摘要 · Abstract (English)
Federated Learning (FL) is an emerging distributed machine learning paradigm enabling multiple clients to train a global model collaboratively without sharing their raw data. While FL enhances data privacy by design, it remains vulnerable to various security and privacy threats. This survey provides a comprehensive overview of more than 200 papers regarding the state-of-the-art attacks and defense mechanisms developed to address these challenges, categorizing them into security-enhancing and privacy-preserving techniques. Security-enhancing methods aim to improve FL robustness against malicious behaviors such as byzantine attacks, poisoning, and Sybil attacks. At the same time, privacy-preserving techniques focus on protecting sensitive data through cryptographic approaches, differential privacy, and secure aggregation. We critically analyze the strengths and limitations of existing methods, highlight the trade-offs between privacy, security, and model performance, and discuss the implications of non-IID data distributions on the effectiveness of these defenses. Furthermore, we identify open research challenges and future directions, including the need for scalable, adaptive, and energy-efficient solutions operating in dynamic and heterogeneous FL environments. Our survey aims to guide researchers and practitioners in developing robust and privacy-preserving FL systems, fostering advancements safeguarding collaborative learning frameworks' integrity and confidentiality.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。