提出ARMOR框架,提升移动端持续联邦定位的抗攻击能力。
ARMOR: Adaptive Resilience Against Model Poisoning Attacks in Continual Federated Learning for Mobile Indoor Localization
- 用状态空间模型追踪全局模型权重演化趋势
- 检测并过滤异常更新,使平均误差降低8.0倍
- 适合部署在设备异构、环境动态变化的定位系统
室内定位在资产追踪与个性化服务中日益重要。联邦学习(FL)通过不共享原始数据,在移动设备上分布式训练中心化全局模型(GM),保护隐私。但实际应用需持续联邦学习(CFL)场景,面对设备异构与环境演变,错误或偏斜的更新会偏离模型预期轨迹,逐步破坏内部表征与定位性能,且易受对抗性模型投毒攻击影响。为此,本文提出ARMOR框架,利用新颖的状态空间模型(SSM)学习全局模型权重张量的历史演化,预测其下一状态。通过比对本地更新与SSM预测值,检测偏差并选择性缓解污染更新,防止聚合前模型被篡改。该机制可有效适应时间动态环境,抵御投毒攻击。真实场景实验表明,相较于现有先进框架,ARMOR实现平均误差最高降低8.0倍,最坏情况误差降低4.97倍,验证了其在真实数据与移动设备上的强抗污染鲁棒性。
原文摘要 · Abstract (English)
Indoor localization has become increasingly essential for applications ranging from asset tracking to delivering personalized services. Federated learning (FL) offers a privacy-preserving approach by training a centralized global model (GM) using distributed data from mobile devices without sharing raw data. However, real-world deployments require a continual federated learning (CFL) setting, where the GM receives continual updates under device heterogeneity and evolving indoor environments. In such dynamic conditions, erroneous or biased updates can cause the GM to deviate from its expected learning trajectory, gradually degrading internal GM representations and GM localization performance. This vulnerability is further exacerbated by adversarial model poisoning attacks. To address this challenge, we propose ARMOR, a novel CFL-based framework that monitors and safeguards the GM during continual updates. ARMOR introduces a novel state-space model (SSM) that learns the historical evolution of GM weight tensors and predicts the expected next state of weight tensors of the GM. By comparing incoming local updates with this SSM projection, ARMOR detects deviations and selectively mitigates corrupted updates before local updates are aggregated with the GM. This mechanism enables robust adaptation to temporal environmental dynamics and mitigate the effects of model poisoning attacks while preventing GM corruption. Experimental evaluations in real-world conditions indicate that ARMOR achieves notable improvements, with up to 8.0x reduction in mean error and 4.97x reduction in worst-case error compared to state-of-the-art indoor localization frameworks, demonstrating strong resilience against model corruption tested using real-world data and mobile devices.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。