只传部分模型参数,让联邦预测更抗恶意攻击且通信更省。
Partial Model Sharing Improves Byzantine Resilience in Federated Conformal Prediction
- 每轮只交换部分模型参数,缩小攻击面并减少通信量。
- 在多种恶意攻击下,预测覆盖率接近理论值,区间更紧凑。
- 适合对安全性与效率要求高的联邦学习场景。
我们提出一种抗拜占庭攻击的联邦共形预测(FCP)方法,采用部分模型共享机制,即每轮仅交换模型参数的子集。与现有方法主要强化校准阶段不同,本方法同时保护联邦训练和共形校准两个阶段。训练阶段,部分共享天然限制了攻击面并削弱污染更新,同时降低通信开销;校准阶段,客户端将非一致性分数压缩为基于直方图的表征向量,服务器通过距离式恶意度评分检测拜占庭客户端,并仅用良性贡献者估计共形分位数。在多种拜占庭攻击场景下的实验表明,该方法相比标准FCP实现了更接近名义覆盖概率、且显著更紧的预测区间,构建了一种鲁棒且通信高效的联邦不确定性量化方案。
原文摘要 · Abstract (English)
We propose a Byzantine-resilient federated conformal prediction (FCP) method that leverages partial model sharing, where only a subset of model parameters is exchanged each round. Unlike existing robust FCP approaches that primarily harden the calibration stage, our method protects both the federated training and conformal calibration phases. During training, partial sharing inherently restricts the attack surface and attenuates poisoned updates while reducing communication. During calibration, clients compress their non-conformity scores into histogram-based characterization vectors, enabling the server to detect Byzantine clients via distance-based maliciousness scores and to estimate the conformal quantile using only benign contributors. Experiments across diverse Byzantine attack scenarios show that the proposed method achieves closer-to-nominal coverage with substantially tighter prediction intervals than standard FCP, establishing a robust and communication-efficient approach to federated uncertainty quantification.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。