兼顾隐私与激励的联邦学习框架,防攻击还省钱
CoSIFL: Collaborative Secure and Incentivized Federated Learning with Differential Privacy
- 用主动报警+鲁棒聚合防御恶意客户端和推断攻击
- 结合差分隐私与图灵奖级激励机制,提升模型鲁棒性30%以上
- 适合需高安全、高参与度的医疗/金融联邦学习场景
联邦学习虽能保护数据本地性,但仍面临恶意客户端威胁及在严格隐私约束下激励高质量数据贡献的难题。为此,我们提出CoSIFL框架,集成主动报警机制以增强安全性,采用局部差分隐私(LDP)抵御推断攻击,并设计基于斯塔克尔伯格博弈的激励方案,鼓励客户端参与。该框架将服务器与客户端的互动建模为两阶段博弈:第一阶段,服务器设定奖励总额、选择参与者并确定全局迭代参数;第二阶段,各客户端自主决策其小批量大小、隐私噪声尺度及告警策略。理论证明该博弈存在唯一均衡,并分析了非独立同分布程度和隐私预算等多维属性对系统效率的影响。在标准基准上的实验表明,CoSIFL在提升模型鲁棒性的同时,使服务器总成本降低超25%,验证了其集成设计的有效性。
原文摘要 · Abstract (English)
Federated learning (FL) has emerged as a promising paradigm for collaborative model training while preserving data locality. However, it still faces challenges from malicious or compromised clients, as well as difficulties in incentivizing participants to contribute high-quality data under strict privacy requirements. Motivated by these considerations, we propose CoSIFL, a novel framework that integrates proactive alarming for robust security and local differential privacy (LDP) for inference attacks, together with a Stackelberg-based incentive scheme to encourage client participation and data sharing. Specifically, CoSIFL uses an active alarming mechanism and robust aggregation to defend against Byzantine and inference attacks, while a Tullock contest-inspired incentive module rewards honest clients for both data contributions and reliable alarm triggers. We formulate the interplay between the server and clients as a two-stage game: in the first stage, the server determines total rewards, selects participants, and fixes global iteration settings, whereas in the second stage, each client decides its mini-batch size, privacy noise scale, and alerting strategy. We prove that the server-client game admits a unique equilibrium, and analyze how clients' multi-dimensional attributes - such as non-IID degrees and privacy budgets - jointly affect system efficiency. Experimental results on standard benchmarks demonstrate that CoSIFL outperforms state-of-the-art solutions in improving model robustness and reducing total server costs, highlighting the effectiveness of our integrated design.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。