arXiv:2602.18396cs.LGeess.SP2026-02

通过部分模型共享与统计边界,实现高效抗攻击的联邦不确定性量化。

Communication-Efficient Byzantine-Robust Federated Conformal Prediction via Partial Model Sharing

  • 训练时仅传输部分参数,降低恶意更新影响
  • 校准阶段用距离判别异常贡献,避免预测区间膨胀
  • 适合对通信成本和鲁棒性要求高的联邦学习场景

我们提出PRISM-FCP(Partial shaRing and robust calIbration with Statistical Margins for Federated Conformal Prediction),一种通信高效且抗拜占庭攻击的联邦共形预测框架。在训练阶段,客户端每轮仅传输D个参数中的M个,使恶意扰动在聚合更新中的期望能量降低M/D倍,从而减小均方误差(MSE)并获得更紧的预测区间。在校准阶段,客户端将非一致性分数转换为特征向量,基于距离计算恶意度得分,并对可疑的拜占庭贡献进行加权或过滤后估计共形分位数。在合成数据和UCI Superconductivity数据集上的大量实验表明,PRISM-FCP在所研究的拜占庭设置下保持接近名义的实证覆盖率,同时避免了标准FCP中出现的区间膨胀问题,且通信开销更低。结果支持其作为鲁棒且高效的联邦不确定性量化方法。

原文摘要 · Abstract (English)

We propose PRISM-FCP (Partial shaRing and robust calIbration with Statistical Margins for Federated Conformal Prediction), a communication-efficient Byzantine-robust federated conformal prediction framework that uses partial model sharing to mitigate stochastic model-poisoning attacks during training and histogram-based filtering to mitigate adversarial calibration submissions. Existing approaches address adversarial behavior only in the calibration stage, leaving the learned model susceptible to poisoned updates. In contrast, PRISM-FCP mitigates attacks end-to-end. During training, clients partially share updates by transmitting only $M$ of $D$ parameters per round. This attenuates the expected energy of an adversary's perturbation in the aggregated update by a factor of $M/D$, yielding lower mean-square error (MSE) and tighter prediction intervals. During calibration, clients convert nonconformity scores into characterization vectors, compute distance-based maliciousness scores, and downweight or filter suspected Byzantine contributions before estimating the conformal quantile. Extensive experiments on both synthetic data and the UCI Superconductivity dataset demonstrate that PRISM-FCP maintains near-nominal empirical coverage in the studied Byzantine settings while avoiding the interval inflation observed in standard FCP, with reduced communication. These results support PRISM-FCP as a robust and communication-efficient approach to federated uncertainty quantification.

联邦学习不确定性量化抗攻击通信效率

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。