arXiv:2510.01261cs.LGcs.CR2025-10被引 1

用智能体决策机制提升联邦学习抗攻击能力

Adaptive Federated Learning Defences via Trust-Aware Deep Q-Networks

  • 设计信任感知的深度强化学习框架,融合多信号动态评估客户端可信度
  • 在CIFAR-10上实现稳定准确率,攻击成功率降低至12.3%以下
  • 适合关注联邦学习安全与长期鲁棒性的研究人员

联邦学习在部分可观测条件下易受投毒和后门攻击。我们将防御建模为部分可观测的序列决策问题,提出一种信任感知的深度Q网络,通过整合多源信号证据进行客户端信任更新,并优化长期鲁棒性-准确率目标。在CIFAR-10上,(i) 建立基线,显示准确率持续提升;(ii) 通过狄利克雷分布扫描表明,客户端重叠度增加可稳定提升准确率并降低攻击成功率(ASR);(iii) 在信号预算研究中,当可观测性下降时,准确率保持稳定,但攻击成功率上升,ROC-AUC下降,说明序列信念更新能缓解弱信号影响。与随机、线性Q及策略梯度控制器相比,DQN在鲁棒性-准确率权衡上表现最优。

原文摘要 · Abstract (English)

Federated learning is vulnerable to poisoning and backdoor attacks under partial observability. We formulate defence as a partially observable sequential decision problem and introduce a trust-aware Deep Q-Network that integrates multi-signal evidence into client trust updates while optimizing a long-horizon robustness--accuracy objective. On CIFAR-10, we (i) establish a baseline showing steadily improving accuracy, (ii) show through a Dirichlet sweep that increased client overlap consistently improves accuracy and reduces ASR with stable detection, and (iii) demonstrate in a signal-budget study that accuracy remains steady while ASR increases and ROC-AUC declines as observability is reduced, which highlights that sequential belief updates mitigate weaker signals. Finally, a comparison with random, linear-Q, and policy gradient controllers confirms that DQN achieves the best robustness--accuracy trade-off.

联邦学习安全防御强化学习信任机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。