提出双视角梯度检测机制,提升非独立同分布下的抗攻击联邦学习能力。
ProDiGy: Proximity- and Dissimilarity-Based Byzantine-Robust Federated Learning
- 通过梯度近似与差异性联合评分,识别恶意客户端
- 在非独立同分布数据下仍保持高模型准确率
- 适合数据异构场景下的安全联邦学习应用
联邦学习(FL)作为一种分布式学习范式受到广泛关注。尽管具有诸多优势,FL 在数据异构条件下仍易受对抗攻击。本文提出一种新型抗拜占庭攻击的联邦学习算法 ProDiGy,其核心创新在于基于梯度的近似性与差异性构建联合双评分系统来评估客户端梯度。通过大量数值实验表明,ProDiGy 在多种场景下均优于现有防御方法。尤其在客户端数据非独立同分布(non-IID)时,其他防御机制失效,而 ProDiGy 仍能维持强防御能力与模型精度。结果表明,双视角方法既能促进诚实客户端间的自然相似性,又能将异常一致性作为攻击指示信号,具备显著有效性。
原文摘要 · Abstract (English)
Federated Learning (FL) emerged as a widely studied paradigm for distributed learning. Despite its many advantages, FL remains vulnerable to adversarial attacks, especially under data heterogeneity. We propose a new Byzantine-robust FL algorithm called ProDiGy. The key novelty lies in evaluating the client gradients using a joint dual scoring system based on the gradients' proximity and dissimilarity. We demonstrate through extensive numerical experiments that ProDiGy outperforms existing defenses in various scenarios. In particular, when the clients' data do not follow an IID distribution, while other defense mechanisms fail, ProDiGy maintains strong defense capabilities and model accuracy. These findings highlight the effectiveness of a dual perspective approach that promotes natural similarity among honest clients while detecting suspicious uniformity as a potential indicator of an attack.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。