arXiv:2512.17254cs.CRcs.DC2025-12中稿 · publication in IEE…被引 4

提出轻量级框架ABBR,兼顾联邦学习的抗攻击与隐私保护。

Practical Framework for Privacy-Preserving and Byzantine-robust Federated Learning

  • 用降维加速隐私保护中的复杂过滤计算
  • 自适应调参减少恶意模型对全局模型的影响
  • 在多个数据集上验证高效且接近基线鲁棒性

联邦学习(FL)允许多个客户端在不共享私有数据的情况下协同训练模型。然而,FL易受拜占庭攻击影响,即敌手篡改客户端模型以破坏全局模型;同时面临隐私推断攻击,敌手通过分析客户端模型反推私有数据。现有防御方法在对抗后门和隐私推断攻击时引入显著计算与通信开销,理论与实践存在差距。为此,我们提出ABBR,一种实用的抗拜占庭与隐私保护联邦学习框架。首次利用降维加速隐私保护中复杂过滤规则的私有计算。分析向量级过滤在低维空间下的精度损失,并提出自适应调参策略,最小化绕过过滤的恶意模型对全局模型的影响。在公开数据集上实现并评估,结果表明其运行速度显著提升,通信开销极小,且保持与基线相当的拜占庭鲁棒性。

原文摘要 · Abstract (English)

Federated Learning (FL) allows multiple clients to collaboratively train a model without sharing their private data. However, FL is vulnerable to Byzantine attacks, where adversaries manipulate client models to compromise the federated model, and privacy inference attacks, where adversaries exploit client models to infer private data. Existing defenses against both backdoor and privacy inference attacks introduce significant computational and communication overhead, creating a gap between theory and practice. To address this, we propose ABBR, a practical framework for Byzantine-robust and privacy-preserving FL. We are the first to utilize dimensionality reduction to speed up the private computation of complex filtering rules in privacy-preserving FL. Additionally, we analyze the accuracy loss of vector-wise filtering in low-dimensional space and introduce an adaptive tuning strategy to minimize the impact of malicious models that bypass filtering on the global model. We implement ABBR with state-of-the-art Byzantine-robust aggregation rules and evaluate it on public datasets, showing that it runs significantly faster, has minimal communication overhead, and maintains nearly the same Byzantine-resilience as the baselines.

联邦学习隐私保护鲁棒性降维

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。