arXiv:2602.21721cs.CRcs.GT2026-02

提出可兼容安全聚合的公平鲁棒贡献评估方法。

Private and Robust Contribution Evaluation in Federated Learning

  • 设计两种适配安全聚合的边际差异贡献评分机制。
  • 在医学图像与CIFAR10数据上优于基线,更接近谢尔普利值排序。
  • 适合需要隐私保护与防操纵的跨组织联邦学习场景。

跨库联邦学习允许多个机构协作训练模型而不共享原始数据,但客户端更新仍可能通过推断攻击泄露敏感信息。安全聚合通过隐藏个体更新保护隐私,却使贡献评估复杂化,而贡献评估对公平奖励和检测低质量或恶意参与者至关重要。现有基于边际贡献的方法(如谢尔普利值)与安全聚合不兼容,实用替代方案(如留一法)粗糙且依赖自我评估。本文提出两种适配安全聚合的边际差异贡献评分:Fair-Private满足标准公平公理,Everybody-Else消除自我评估并具备抗操纵性,解决长期被忽视的漏洞。我们提供公平性、隐私性、鲁棒性和计算效率的理论保证,并在多个医学图像数据集和CIFAR10上评估方法。结果表明,所提评分始终优于现有基线,更准确逼近谢尔普利值诱导的客户排名,同时提升下游模型性能并增强异常行为检测能力。这些结果证明,在联邦贡献评估中,公平性、隐私性、鲁棒性与实用性可协同实现,为真实跨库部署提供了原则性解决方案。

原文摘要 · Abstract (English)

Cross-silo federated learning allows multiple organizations to collaboratively train machine learning models without sharing raw data, but client updates can still leak sensitive information through inference attacks. Secure aggregation protects privacy by hiding individual updates, yet it complicates contribution evaluation, which is critical for fair rewards and detecting low-quality or malicious participants. Existing marginal-contribution methods, such as the Shapley value, are incompatible with secure aggregation, and practical alternatives, such as Leave-One-Out, are crude and rely on self-evaluation. We introduce two marginal-difference contribution scores compatible with secure aggregation. Fair-Private satisfies standard fairness axioms, while Everybody-Else eliminates self-evaluation and provides resistance to manipulation, addressing a largely overlooked vulnerability. We provide theoretical guarantees for fairness, privacy, robustness, and computational efficiency, and evaluate our methods on multiple medical image datasets and CIFAR10 in cross-silo settings. Our scores consistently outperform existing baselines, better approximate Shapley-induced client rankings, and improve downstream model performance as well as misbehavior detection. These results demonstrate that fairness, privacy, robustness, and practical utility can be achieved jointly in federated contribution evaluation, offering a principled solution for real-world cross-silo deployments.

联邦学习隐私保护贡献评估安全聚合

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。