用服务器学习提升联邦学习抗恶意攻击能力,即使客户端数据分布不均。
Enhancing Robustness of Federated Learning via Server Learning
- 服务器学习结合几何中位数聚合与客户端更新过滤
- 当恶意客户端超50%时仍显著提升模型准确率
- 适用于数据少或合成数据的场景,适合安全敏感应用
本文研究在客户端数据非独立同分布的情况下,利用服务器学习增强联邦学习对恶意攻击的鲁棒性。提出一种启发式算法,结合服务器学习、客户端更新过滤与几何中位数聚合。实验表明,该方法在恶意客户端比例超过50%时仍能显著提升模型准确率,且服务器使用的数据量小,可为合成数据,其分布无需接近客户端数据分布。
原文摘要 · Abstract (English)
This paper explores the use of server learning for enhancing the robustness of federated learning against malicious attacks even when clients' training data are not independent and identically distributed. We propose a heuristic algorithm that uses server learning and client update filtering in combination with geometric median aggregation. We demonstrate via experiments that this approach can achieve significant improvement in model accuracy even when the fraction of malicious clients is high, even more than $50\%$ in some cases, and the dataset utilized by the server is small and could be synthetic with its distribution not necessarily close to that of the clients' aggregated data.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。