arXiv:2511.09294cs.LGcs.AI2025-11

提出防御同时破坏准确率与公平性的新型联邦学习攻击

GuardFed: A Trustworthy Federated Learning Framework Against Dual-Facet Attacks

  • 构建双维度攻击模型,模拟真实世界串通场景
  • 在多个数据集上保持准确率与公平性双优表现
  • 适合关注隐私保护与公平性的联邦学习研究者

联邦学习(FL)可实现隐私保护下的协同建模,但仍易受威胁行为影响,导致模型性能或敏感群体公平性受损。现有研究多聚焦单一目标攻击,而同时损害准确率与公平性的策略尚未充分探索。为此,本文提出双重属性攻击(DFA),包含同步式(S-DFA)与分裂式(Sp-DFA)两种变体,以模拟不同现实串通场景。实验表明,现有鲁棒联邦学习防御方法(如混合聚合策略)难以有效抵御DFAs。为此,我们提出GuardFed,一种自适应防御框架:利用少量干净服务器数据并结合合成样本构建公平感知的参考模型。每轮训练中,通过联合评估客户端的性能偏差与公平性退化,计算双视角信任度,仅聚合可信更新。在真实世界数据集上的大量实验显示,GuardFed在多种非独立同分布及对抗条件下均能稳定保持准确率与公平性,优于现有鲁棒联邦学习方法。

原文摘要 · Abstract (English)

Federated learning (FL) enables privacy-preserving collaborative model training but remains vulnerable to adversarial behaviors that compromise model utility or fairness across sensitive groups. While extensive studies have examined attacks targeting either objective, strategies that simultaneously degrade both utility and fairness remain largely unexplored. To bridge this gap, we introduce the Dual-Facet Attack (DFA), a novel threat model that concurrently undermines predictive accuracy and group fairness. Two variants, Synchronous DFA (S-DFA) and Split DFA (Sp-DFA), are further proposed to capture distinct real-world collusion scenarios. Experimental results show that existing robust FL defenses, including hybrid aggregation schemes, fail to resist DFAs effectively. To counter these threats, we propose GuardFed, a self-adaptive defense framework that maintains a fairness-aware reference model using a small amount of clean server data augmented with synthetic samples. In each training round, GuardFed computes a dual-perspective trust score for every client by jointly evaluating its utility deviation and fairness degradation, thereby enabling selective aggregation of trustworthy updates. Extensive experiments on real-world datasets demonstrate that GuardFed consistently preserves both accuracy and fairness under diverse non-IID and adversarial conditions, achieving state-of-the-art performance compared with existing robust FL methods.

联邦学习安全防御公平性隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。