arXiv:2603.16846cs.LG2026-03

提出动态加权机制,有效防御多种恶意攻击的联邦学习方法

Dynamic Meta-Layer Aggregation for Byzantine-Robust Federated Learning

  • 基于元学习思想动态评估客户端更新可靠性
  • 在多类攻击下准确率提升15%以上,且无需预设阈值
  • 适合医疗、金融等对安全要求高的分布式场景

联邦学习(FL)在医疗、金融和物联网等领域广泛应用,实现协同建模同时保护用户隐私。然而,FL系统易受拜占庭攻击者注入恶意更新的影响,严重损害全局模型性能。现有防御方法多针对特定攻击类型,难以应对无目标攻击(如多标签翻转或噪声与后门组合)。为此,我们提出FedAOT——一种受元学习启发的自适应聚合框架,可有效防御多标签翻转及无目标污染攻击。该方法动态调整客户端更新权重,根据其可靠性抑制恶意影响,无需预设阈值或限制性攻击假设。实验表明,FedAOT在多种数据集和攻击类型下均具强泛化能力,在未见过的攻击场景中仍保持高鲁棒性。结果证明,该方法显著提升模型准确率与安全性,同时保持计算效率,为安全联邦学习提供可扩展的实用解决方案。

原文摘要 · Abstract (English)

Federated Learning (FL) is increasingly applied in sectors like healthcare, finance, and IoT, enabling collaborative model training while safeguarding user privacy. However, FL systems are susceptible to Byzantine adversaries that inject malicious updates, which can severely compromise global model performance. Existing defenses tend to focus on specific attack types and fail against untargeted strategies, such as multi-label flipping or combinations of noise and backdoor patterns. To overcome these limitations, we propose FedAOT-a novel defense mechanism that counters multi-label flipping and untargeted poisoning attacks using a metalearning-inspired adaptive aggregation framework. FedAOT dynamically weights client updates based on their reliability, suppressing adversarial influence without relying on predefined thresholds or restrictive attack assumptions. Notably, FedAOT generalizes effectively across diverse datasets and a wide range of attack types, maintaining robust performance even in previously unseen scenarios. Experimental results demonstrate that FedAOT substantially improves model accuracy and resilience while maintaining computational efficiency, offering a scalable and practical solution for secure federated learning.

联邦学习安全防御拜占庭鲁棒

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。