arXiv:2511.11240cs.LGcs.AI2025-11中稿 · AAAI被引 1

提出首个针对分割联邦学习的自愈防御框架,可检测并修复五类数据投毒攻击。

HealSplit: Towards Self-Healing through Adversarial Distillation in Split Federated Learning

  • 通过构建数据拓扑图,利用异常评分识别中毒样本。
  • 生成语义一致的替代数据,并经一致性验证确保修复质量。
  • 融合多教师对抗蒸馏,提升模型对攻击的鲁棒性,适合隐私保护场景。

分割联邦学习(SFL)是一种新兴的隐私保护分布式学习范式,但易受针对局部特征、标签、碎片化数据及模型权重的复杂数据投毒攻击。现有防御方法主要源自传统联邦学习,因无法获取完整模型更新,在SFL中效果不佳。本文提出HealSplit,首个专为SFL设计的统一防御框架,实现对五类复杂投毒攻击的端到端检测与恢复。其包含三个核心组件:(1) 基于拓扑感知的检测模块,通过在碎片化数据上构建图结构,利用拓扑异常评分(TAS)识别中毒样本;(2) 生成式恢复管道,合成语义一致的替代数据,并由一致性验证学生模型验证;(3) 对抗多教师蒸馏框架,使用普通教师(Vanilla Teacher)的语义监督和异常影响去偏教师(AD Teacher)的异常感知信号,结合拓扑与梯度交互矩阵的一致性进行指导。在四个基准数据集上的大量实验表明,HealSplit持续优于十种最先进防御方法,在多种攻击场景下均展现更优的鲁棒性与防御效果。

原文摘要 · Abstract (English)

Split Federated Learning (SFL) is an emerging paradigm for privacy-preserving distributed learning. However, it remains vulnerable to sophisticated data poisoning attacks targeting local features, labels, smashed data, and model weights. Existing defenses, primarily adapted from traditional Federated Learning (FL), are less effective under SFL due to limited access to complete model updates. This paper presents HealSplit, the first unified defense framework tailored for SFL, offering end-to-end detection and recovery against five sophisticated types of poisoning attacks. HealSplit comprises three key components: (1) a topology-aware detection module that constructs graphs over smashed data to identify poisoned samples via topological anomaly scoring (TAS); (2) a generative recovery pipeline that synthesizes semantically consistent substitutes for detected anomalies, validated by a consistency validation student; and (3) an adversarial multi-teacher distillation framework trains the student using semantic supervision from a Vanilla Teacher and anomaly-aware signals from an Anomaly-Influence Debiasing (AD) Teacher, guided by the alignment between topological and gradient-based interaction matrices. Extensive experiments on four benchmark datasets demonstrate that HealSplit consistently outperforms ten state-of-the-art defenses, achieving superior robustness and defense effectiveness across diverse attack scenarios.

联邦学习对抗防御数据安全自愈系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。