REVERB-FL通过服务器端预留集防御音频分类中的模型投毒,提升联邦学习鲁棒性。
REVERB-FL: Server-Side Adversarial and Reserve-Enhanced Federated Learning for Robust Audio Classification
- 在服务器端用5%预留集重训,结合对抗训练抵御投毒攻击。
- 相比基线方法收敛更快,稳态误差降低,有效缓解非独立同分布偏差。
- 轻量级设计无需修改客户端,适合实际部署的隐私保护音频分类场景。
联邦学习(FL)为音频分类提供了隐私保护的训练范式,但对客户端异质性和投毒攻击极为敏感,恶意客户端可能扭曲全局模型并损害分类性能。为应对音频信号分类中的模型投毒问题,我们提出REVERB-FL,一种轻量级、服务器端的防御机制,结合约5%的小型预留集与前后聚合重训练及对抗训练。每轮本地训练后,服务器在预留集上使用干净数据或额外对抗扰动数据优化全局模型,从而抵消非独立同分布(non-IID)漂移并减轻潜在模型投毒影响,且不增加客户端负担或改变聚合流程。我们理论上证明了该框架的可行性,显示其相较于基准联邦平均法具有更快收敛速度和更低稳态误差。我们在两个开源音频分类数据集上验证,采用不同IID与狄利克雷非IID划分,结果表明REVERB-FL能有效抵御多种设计的本地数据投毒。
原文摘要 · Abstract (English)
Federated learning (FL) enables a privacy-preserving training paradigm for audio classification but is highly sensitive to client heterogeneity and poisoning attacks, where adversarially compromised clients can bias the global model and hinder the performance of audio classifiers. To mitigate the effects of model poisoning for audio signal classification, we present REVERB-FL, a lightweight, server-side defense that couples a small reserve set (approximately 5%) with pre- and post-aggregation retraining and adversarial training. After each local training round, the server refines the global model on the reserve set with either clean or additional adversarially perturbed data, thereby counteracting non-IID drift and mitigating potential model poisoning without adding substantial client-side cost or altering the aggregation process. We theoretically demonstrate the feasibility of our framework, showing faster convergence and a reduced steady-state error relative to baseline federated averaging. We validate our framework on two open-source audio classification datasets with varying IID and Dirichlet non-IID partitions and demonstrate that REVERB-FL mitigates global model poisoning under multiple designs of local data poisoning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。