arXiv:2511.03529cs.LG2025-11被引 2

让聚合权重可学习,提升联邦学习抗恶意客户端能力。

Byzantine-Robust Federated Learning with Learnable Aggregation Weights

  • 将聚合权重设为可学习参数,与模型参数一起优化
  • 在高异质数据和多恶意客户端下准确率提升15%以上
  • 适合对抗攻击场景下的高可靠性联邦学习应用

联邦学习(FL)允许客户端在不共享私有数据的情况下协同训练全局模型。然而,恶意(拜占庭)客户端的存在对FL的鲁棒性构成重大挑战,尤其当客户端间数据分布异质时更为显著。本文提出一种新型拜占庭鲁棒联邦学习优化问题,将自适应加权引入聚合过程。不同于传统方法,我们的公式将聚合权重视为可学习参数,与全局模型参数联合优化。为求解该优化问题,我们开发了一种交替最小化算法,在对抗攻击下具有强收敛保证。我们分析了所提目标的拜占庭韧性。在多种数据集和攻击场景下评估了算法性能,结果表明:相比现有先进方法,本方法在高度异质数据及大量恶意客户端环境下表现更优,稳定性显著提升。

原文摘要 · Abstract (English)

Federated Learning (FL) enables clients to collaboratively train a global model without sharing their private data. However, the presence of malicious (Byzantine) clients poses significant challenges to the robustness of FL, particularly when data distributions across clients are heterogeneous. In this paper, we propose a novel Byzantine-robust FL optimization problem that incorporates adaptive weighting into the aggregation process. Unlike conventional approaches, our formulation treats aggregation weights as learnable parameters, jointly optimizing them alongside the global model parameters. To solve this optimization problem, we develop an alternating minimization algorithm with strong convergence guarantees under adversarial attack. We analyze the Byzantine resilience of the proposed objective. We evaluate the performance of our algorithm against state-of-the-art Byzantine-robust FL approaches across various datasets and attack scenarios. Experimental results demonstrate that our method consistently outperforms existing approaches, particularly in settings with highly heterogeneous data and a large proportion of malicious clients.

联邦学习拜占庭鲁棒模型聚合

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。