arXiv:2512.13955cs.AI2025-12

基于多维信誉的激励机制,提升联邦学习公平性与安全性

MURIM: Multidimensional Reputation-based Incentive Mechanism for Federated Learning

  • 综合信誉、资源、隐私和贡献度分配奖励
  • 公平性提升18%,隐私攻击成功率降低5-9%
  • 适合关注联邦学习安全与激励设计的研究者

联邦学习(FL)作为一种保护隐私的机器学习范式,使参与者共享模型更新而非原始数据。然而,FL仍面临激励不足、隐私风险和资源限制等挑战。评估客户端可靠性对公平激励分配和确保数据有效贡献至关重要。为此,我们提出MURIM——一种多维度信誉激励机制,综合考虑客户端可靠性、隐私、资源容量和公平性,防止恶意或不可靠客户端获得不当奖励。MURIM基于客户端贡献、延迟和信誉分配激励,并配备可靠性验证模块。在MNIST、FMNIST和ADULT Income数据集上的大量实验表明,MURIM使公平性指标最高提升18%,隐私攻击成功率降低5-9%,对投毒和噪声梯度攻击的鲁棒性提升达85%,优于现有最优基线。总体而言,MURIM有效缓解对抗威胁,促进公平真实参与,并在异构动态联邦环境中保持稳定模型收敛。

原文摘要 · Abstract (English)

Federated Learning (FL) has emerged as a leading privacy-preserving machine learning paradigm, enabling participants to share model updates instead of raw data. However, FL continues to face key challenges, including weak client incentives, privacy risks, and resource constraints. Assessing client reliability is essential for fair incentive allocation and ensuring that each client's data contributes meaningfully to the global model. To this end, we propose MURIM, a MUlti-dimensional Reputation-based Incentive Mechanism that jointly considers client reliability, privacy, resource capacity, and fairness while preventing malicious or unreliable clients from earning undeserved rewards. MURIM allocates incentives based on client contribution, latency, and reputation, supported by a reliability verification module. Extensive experiments on MNIST, FMNIST, and ADULT Income datasets demonstrate that MURIM achieves up to 18% improvement in fairness metrics, reduces privacy attack success rates by 5-9%, and improves robustness against poisoning and noisy-gradient attacks by up to 85% compared to state-of-the-art baselines. Overall, MURIM effectively mitigates adversarial threats, promotes fair and truthful participation, and preserves stable model convergence across heterogeneous and dynamic federated settings.

联邦学习激励机制信誉系统隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。