arXiv:2511.02029cs.LGcs.AI2025-11

提出抗恶意客户端的联邦子模优化方法,提升数据代表性质量

RobustFSM: Submodular Maximization in Federated Setting with Malicious Clients

  • 设计鲁棒聚合机制,应对客户端伪造信息攻击
  • 在严重攻击下性能优于传统方法最高达200%
  • 适用于隐私敏感场景下的高效数据采样

子模最大化是许多机器学习应用中的关键优化问题,旨在从海量数据中选出最具代表性的少量样本。本文研究联邦设置下的子模最大化,其中数据由分布式的客户端本地持有,各自定义代表性的质量标准。该设置需反复聚合客户端计算的本地信息。尽管能保护客户端隐私与自主性,却易受恶意客户端攻击:其可能提交虚假信息。这类似于传统联邦学习中的后门攻击,但因子模最大化的特性而面临全新挑战。本文提出RobustFSM,一种对多种实际客户端攻击具有鲁棒性的联邦子模最大化方案。通过真实数据集的实证评估验证其有效性。数值结果显示,在攻击严重时,RobustFSM的解决方案质量显著优于传统联邦算法,提升幅度可达200%,具体效果取决于数据集和攻击场景。

原文摘要 · Abstract (English)

Submodular maximization is an optimization problem benefiting many machine learning applications, where we seek a small subset best representing an extremely large dataset. We focus on the federated setting where the data are locally owned by decentralized clients who have their own definitions for the quality of representability. This setting requires repetitive aggregation of local information computed by the clients. While the main motivation is to respect the privacy and autonomy of the clients, the federated setting is vulnerable to client misbehaviors: malicious clients might share fake information. An analogy is backdoor attack in conventional federated learning, but our challenge differs freshly due to the unique characteristics of submodular maximization. We propose RobustFSM, a federated submodular maximization solution that is robust to various practical client attacks. Its performance is substantiated with an empirical evaluation study using real-world datasets. Numerical results show that the solution quality of RobustFSM substantially exceeds that of the conventional federated algorithm when attacks are severe. The degree of this improvement depends on the dataset and attack scenarios, which can be as high as 200%

联邦学习子模优化安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。