arXiv:2603.19101cs.CRcs.AI2026-03

防御联邦学习中车辆恶意篡改道路状态数据,提升交通系统安全

FedTrident: Resilient Road Condition Classification Against Poisoning Attacks in Federated Learning

  • 通过神经元级分析识别恶意客户端的异常行为
  • 动态评分排除恶意车辆,修复已被污染的全局模型
  • 在多种攻击和数据差异下仍保持高鲁棒性,适合智能交通应用

联邦学习(FL)在智能交通系统中推动了基于摄像头的道路状态分类(RCC),但其协作机制使系统易受目标标签翻转攻击(TLFA)威胁。恶意客户端(如车辆)可篡改本地训练数据标签(如将不平路面标记为平滑),导致全局模型预测错误,危及交通安全。现有防御方法因未针对TLFA设计检测机制、缺乏基于历史行为的客户端剔除策略,以及无法修复已污染的全局模型而效果不佳。为此,我们提出FedTrident,包含:1)神经元级分析实现本地模型异常检测(含攻击目标识别、关键特征提取与基于高斯混合模型的聚类过滤);2)根据每轮检测结果自适应调整客户端评分并剔除恶意节点;3)在剔除后通过机器遗忘技术修复已被污染的全局模型。跨多种联邦RCC模型、任务与配置的实证表明,FedTrident能有效抵御TLFA,性能接近无攻击场景,在两个核心指标上分别优于8个基线方法9.49%和4.47%。此外,该方法对不同恶意客户端比例、数据异质性、多任务及动态攻击均具强鲁棒性。

原文摘要 · Abstract (English)

FL has emerged as a transformative paradigm for ITS, notably camera-based Road Condition Classification (RCC). However, by enabling collaboration, FL-based RCC exposes the system to adversarial participants launching Targeted Label-Flipping Attacks (TLFAs). Malicious clients (vehicles) can relabel their local training data (e.g., from an actual uneven road to a wrong smooth road), consequently compromising global model predictions and jeopardizing transportation safety. Existing countermeasures against such poisoning attacks fail to maintain resilient model performance near the necessary attack-free levels in various attack scenarios due to: 1) not tailoring poisoned local model detection to TLFAs, 2) not excluding malicious vehicular clients based on historical behavior, and 3) not remedying the already-corrupted global model after exclusion. To close this research gap, we propose FedTrident, which introduces: 1) neuron-wise analysis for local model misbehavior detection (notably including attack goal identification, critical feature extraction, and GMM-based model clustering and filtering); 2) adaptive client rating for client exclusion according to the local model detection results in each FL round; and 3) machine unlearning for corrupted global model remediation once malicious clients are excluded during FL. Extensive evaluation across diverse FL-RCC models, tasks, and configurations demonstrates that FedTrident can effectively thwart TLFAs, achieving performance comparable to that in attack-free scenarios and outperforming eight baseline countermeasures by 9.49% and 4.47% for the two most critical metrics. Moreover, FedTrident is resilient to various malicious client rates, data heterogeneity levels, complicated multi-task, and dynamic attacks.

联邦学习道路分类对抗攻击智能交通

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。