联邦学习中的贡献评分易受模型聚合和恶意攻击干扰,影响公平性。
On the Fragility of Contribution Score Computation in Federated Learning
- 不同聚合方法会无意中改变参与方的贡献评分
- 恶意攻击者可篡改更新以虚高自身评分
- 适用于关注联邦学习公平激励机制的研究者
本文研究联邦学习中贡献评估的脆弱性,这一机制对确保公平性和激励参与至关重要。我们指出,贡献评分易受两个根本因素的显著扭曲:架构敏感性和有意操纵。首先,我们探讨不同模型聚合方法对评分的影响。尽管多数研究假设采用基础平均法,但我们证明,旨在应对不可靠或异构客户端的先进聚合技术,可能无意中且显著改变最终评分。其次,我们研究了投毒攻击带来的漏洞,恶意参与者可战略性地篡改其模型更新,以虚增自身贡献评分或降低其他参与方的重要性。通过在多种数据集和模型架构上、基于Flower框架的大量实验,我们严谨表明,聚合方法的选择与攻击者存在均是导致评分扭曲的强大因素,凸显了构建更鲁棒评估方案的迫切需求。
原文摘要 · Abstract (English)
This paper investigates the fragility of contribution evaluation in federated learning, a critical mechanism for ensuring fairness and incentivizing participation. We argue that contribution scores are susceptible to significant distortions from two fundamental perspectives: architectural sensitivity and intentional manipulation. First, we explore how different model aggregation methods impact these scores. While most research assumes a basic averaging approach, we demonstrate that advanced techniques, including those designed to handle unreliable or diverse clients, can unintentionally yet significantly alter the final scores. Second, we explore vulnerabilities posed by poisoning attacks, where malicious participants strategically manipulate their model updates to inflate their own contribution scores or reduce the importance of other participants. Through extensive experiments across diverse datasets and model architectures, implemented within the Flower framework, we rigorously show that both the choice of aggregation method and the presence of attackers are potent vectors for distorting contribution scores, highlighting a critical need for more robust evaluation schemes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。