arXiv:2509.18044cs.CRcs.AI2025-09被引 4

提出混合信誉聚合机制,有效防御5G边缘联邦学习中的各类恶意攻击。

Hybrid Reputation Aggregation: A Robust Defense Mechanism for Adversarial Federated Learning in 5G and Edge Network Environments

  • 结合几何异常检测与动态信誉追踪,实时识别异常模型更新。
  • 在300万条数据的5G数据集上达到98.66%准确率,显著优于现有方法。
  • 适合部署于高安全需求的5G/边缘计算场景,尤其对抗未知攻击。

5G与边缘网络环境下的联邦学习面临严重的恶意客户端威胁,攻击者可实施标签翻转、注入后门或发起Sybil攻击以污染全局模型。本文提出混合信誉聚合(HRA)机制,一种无需预先知晓攻击类型即可防御多种恶意行为的鲁棒聚合方法。HRA融合基于距离的几何异常检测与基于动量的客户端信誉追踪:每轮通过几何分析识别模型更新异常,同时根据历史行为持续更新客户端信任分。该双机制实现对可疑更新的自适应过滤及对不可靠客户端的长期惩罚,有效应对从后门注入到随机噪声型拜占庭故障等多种攻击。我们在大规模专有5G网络数据集(300万+记录)和广泛使用的NF-CSE-CIC-IDS2018基准上评估了HRA,在多种攻击场景下表现优异,5G数据集上全局模型准确率达98.66%,在NF-CSE-CIC-IDS2018上达96.60%,显著优于Krum、Trimmed Mean、Bulyan等前沿聚合器。消融实验表明,完整系统达98.66%准确率,仅异常检测或仅信誉追踪的变体分别降至84.77%和78.52%,验证了双机制协同的价值。结果表明,HRA在5G/边缘联邦学习中具备更强的抗干扰能力,即使在强敌手环境下仍保持高度鲁棒性。

原文摘要 · Abstract (English)

Federated Learning (FL) in 5G and edge network environments face severe security threats from adversarial clients. Malicious participants can perform label flipping, inject backdoor triggers, or launch Sybil attacks to corrupt the global model. This paper introduces Hybrid Reputation Aggregation (HRA), a novel robust aggregation mechanism designed to defend against diverse adversarial behaviors in FL without prior knowledge of the attack type. HRA combines geometric anomaly detection with momentum-based reputation tracking of clients. In each round, it detects outlier model updates via distance-based geometric analysis while continuously updating a trust score for each client based on historical behavior. This hybrid approach enables adaptive filtering of suspicious updates and long-term penalization of unreliable clients, countering attacks ranging from backdoor insertions to random noise Byzantine failures. We evaluate HRA on a large-scale proprietary 5G network dataset (3M+ records) and the widely used NF-CSE-CIC-IDS2018 benchmark under diverse adversarial attack scenarios. Experimental results reveal that HRA achieves robust global model accuracy of up to 98.66% on the 5G dataset and 96.60% on NF-CSE-CIC-IDS2018, outperforming state-of-the-art aggregators such as Krum, Trimmed Mean, and Bulyan by significant margins. Our ablation studies further demonstrate that the full hybrid system achieves 98.66% accuracy, while the anomaly-only and reputation-only variants drop to 84.77% and 78.52%, respectively, validating the synergistic value of our dual-mechanism approach. This demonstrates HRA's enhanced resilience and robustness in 5G/edge federated learning deployments, even under significant adversarial conditions.

联邦学习5G安全恶意客户端信誉机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。