arXiv:2603.19314cs.LGcs.CR2026-03中稿 · AI FOR FINANCIAL F…被引 2

基于信誉加权的自适应差分隐私,提升反洗钱联邦学习的隐私与性能平衡。

DPxFin: Adaptive Differential Privacy for Anti-Money Laundering Detection via Reputation-Weighted Federated Learning

  • 根据客户端模型与全局模型的一致性动态评估信誉,决定差分隐私噪声大小。
  • 在非独立同分布数据下,准确率比传统方法提升约5.2%,隐私保护更强。
  • 适合金融领域需高隐私保护的联邦学习场景,尤其对抗数据泄露攻击。

在现代金融体系中,打击洗钱是一项关键挑战,其复杂性源于数据隐私顾虑和日益复杂的欺诈交易模式。尽管联邦学习(FL)通过不共享数据即可训练模型而成为有前景的解决方案,但在表格数据(如金融数据)场景下仍存在隐私泄露风险。为此,我们提出DPxFin,一种融合信誉引导的自适应差分隐私的新型联邦学习框架。该方法通过评估本地训练模型与全局模型的一致性来计算客户端信誉,并据此动态分配差分隐私噪声:高信誉客户端获得较低噪声以增强可信贡献,低信誉客户端则分配更强噪声以降低风险。我们在反洗钱(AML)数据集上,采用多层感知机(MLP)在独立同分布(IID)与非独立同分布(non-IID)设置下验证了该方法。实验表明,相比传统联邦学习与固定噪声差分隐私基线,DPxFin在准确率与隐私保护之间实现了更优权衡,性能提升稳定,即使幅度较小。此外,DPxFin能有效抵御表格数据泄露攻击,证明其在真实金融环境下的有效性。

原文摘要 · Abstract (English)

In the modern financial system, combating money laundering is a critical challenge complicated by data privacy concerns and increasingly complex fraud transaction patterns. Although federated learning (FL) is a promising problem-solving approach as it allows institutions to train their models without sharing their data, it has the drawback of being prone to privacy leakage, specifically in tabular data forms like financial data. To address this, we propose DPxFin, a novel federated framework that integrates reputation-guided adaptive differential privacy. Our approach computes client reputation by evaluating the alignment between locally trained models and the global model. Based on this reputation, we dynamically assign differential privacy noise to client updates, enhancing privacy while maintaining overall model utility. Clients with higher reputations receive lower noise to amplify their trustworthy contributions, while low-reputation clients are allocated stronger noise to mitigate risk. We validate DPxFin on the Anti-Money Laundering (AML) dataset under both IID and non-IID settings using Multi Layer Perceptron (MLP). Experimental analysis established that our approach has a more desirable trade-off between accuracy and privacy than those of traditional FL and fixed-noise Differential Privacy (DP) baselines, where performance improvements were consistent, even though on a modest scale. Moreover, DPxFin does withstand tabular data leakage attacks, proving its effectiveness under real-world financial conditions.

联邦学习差分隐私反洗钱信誉机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。