提出自适应多层防御聚合机制,提升联邦学习抗恶意攻击能力。
AdaBFL: Multi-Layer Defensive Adaptive Aggregation for Bzantine-Robust Federated Learning

- 设计三层防御机制,动态调整各防御算法权重。
- 在非凸非独立同分布数据下证明方法收敛性。
- 无需服务器持有数据集,适用于多种攻击场景。
联邦学习(FL)是一种流行的分布式机器学习范式,允许多个客户端在服务器指导下协同训练模型,同时保护客户端数据隐私。然而,其去中心化特性使其易受投毒攻击,恶意客户端可通过提交污染模型来操纵系统。尽管已有多种拜占庭鲁棒方法,但这些方法难以平衡应对多种攻击类型,或依赖服务器拥有数据集。为此,本文提出一种面向拜占庭鲁棒联邦学习的多层防御自适应聚合方法(AdaBFL),基于新颖的三层防御机制,可自适应调整防御算法权重以应对复杂攻击。此外,在非独立同分布(non-iid)数据的非凸设定下,我们证明了所提方法的收敛性。在多个数据集上的综合实验验证了其相较于对比算法的优越性。
原文摘要 · Abstract (English)
Federated learning (FL) is a popular distributed learning paradigm in machine learning, which enables multiple clients to collaboratively train models under the guidance of a server without exposing private client data. However, FL's decentralized nature makes it vulnerable to poisoning attacks, where malicious clients can submit corrupted models to manipulate the system. To counter such attacks, although various Byzantine-robust methods have been proposed, these methods struggle to provide balanced defense against multiple types of attacks or rely on possessing the dataset in the server. To deal with these drawbacks, thus, we propose an effective multi-layer defensive adaptive aggregation for Bzantine-robust federated learning (AdaBFL) based on a novel three-layer defensive mechanism, which can adaptively adjust the weights of defense algorithms to counter complex attacks. Moreover, we provide convergence properties of our AdaBFL method under the non-convex setting on non-iid data. Comprehensive experiments across multiple datasets validate the superiority of our AdaBFL over the comparable algorithms.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。