通过分布匹配快速稳定地识别并过滤恶意客户端,提升联邦学习鲁棒性。
FedIDM: Achieving Fast and Stable Convergence in Byzantine Federated Learning through Iterative Distribution Matching

- 用分布匹配生成可信数据集,识别异常客户端
- 在多轮攻击下仍保持收敛速度与模型性能
- 适合高比例恶意节点场景下的安全联邦学习
现有拜占庭鲁棒联邦学习方法普遍存在收敛慢、不稳定的问题。当存在大量串通恶意客户端时,传统方法常以牺牲模型效用为代价换取鲁棒性。本文提出FedIDM,通过分布匹配构建可信压缩数据集,用于识别和过滤异常客户端。该方法包含两个核心组件:(1) 攻击容忍的压缩数据生成;(2) 基于负贡献的鲁棒聚合。通过排除与压缩数据更新方向偏离或在压缩数据集上导致显著损失的本地更新,有效提升系统稳定性。在三个基准数据集上的全面评估表明,即使面对多个先进拜占庭攻击且恶意客户端占比高,FedIDM仍能实现快速稳定收敛,并保持可接受的模型性能。
原文摘要 · Abstract (English)
Most existing Byzantine-robust federated learning (FL) methods suffer from slow and unstable convergence. Moreover, when handling a substantial proportion of colluded malicious clients, achieving robustness typically entails compromising model utility. To address these issues, this work introduces FedIDM, which employs distribution matching to construct trustworthy condensed data for identifying and filtering abnormal clients. FedIDM consists of two main components: (1) attack-tolerant condensed data generation, and (2) robust aggregation with negative contribution-based rejection. These components exclude local updates that (1) deviate from the update direction derived from condensed data, or (2) cause a significant loss on the condensed dataset. Comprehensive evaluations on three benchmark datasets demonstrate that FedIDM achieves fast and stable convergence while maintaining acceptable model utility, under multiple state-of-the-art Byzantine attacks involving a large number of malicious clients.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。