发现个性化联邦学习易受攻击,提出协同防御方案提升系统鲁棒性。
Towards Robust Personalized Federated Learning: Vulnerability Assessment and Defense Co-Design

- 分析个性化联邦学习的模型漏洞,揭示其对迁移攻击更敏感。
- 实验证明攻击可使多种PFL方法准确率大幅下降。
- 设计噪声注入与正则化联合防御,适配物联网设备部署。
物联网设备的普及推动了分布式边缘系统的兴起,为本地机器学习应用提供了海量敏感数据。尽管联邦学习(FL)通过交换模型参数而非原始数据缓解了隐私问题,但当前研究存在关键盲区。本文系统分析了最常用的个性化联邦学习(PFL)方法——该方法允许客户端保留私有、个性化的模型以应对客户端间的数据异构性。通过理论与实证结合,我们发现PFL方法相比集中式学习对基于迁移的对抗攻击表现出更高脆弱性:恶意客户端可利用本地模型知识构造对抗样本,进而破坏其他客户端的个性化模型。该结论在多个基准数据集上得到验证,显示各类PFL方法均出现显著准确率下降。为此,我们提出一种融合随机输入噪声、输入缩放迹正则化与参数敏感性最大化的协同防御框架,显著增强系统鲁棒性。本研究首次系统揭示了PFL中的对抗威胁,提供诊断工具与实用防御策略。
原文摘要 · Abstract (English)
The proliferation of IoT devices has fueled distributed edge systems to collect vast amounts of sensitive data, creating fertile ground for on-device machine learning applications. While federated learning (FL) mitigates privacy concerns by exchanging model parameters instead of raw data, we identify a critical blind spot in current research. We examine the most commonly used personalized federated learning (PFL) methods, which allow clients to maintain private, personalized models to address data heterogeneity across clients. Through systematic analysis, we reveal that PFL methods exhibit heightened vulnerability to transfer-based adversarial attacks compared to centralized learning paradigms. Wherein, malicious clients can exploit local model knowledge to craft adversarial examples that can compromise peer clients' personalized models. We establish this vulnerability through both theoretical analysis and empirical evaluation across multiple benchmark datasets, demonstrating significant accuracy drops across various PFL methods. To address this challenge, we propose a defense framework combining stochastic input noise, input-scaled trace regularization, and parameter sensitivity maximization to improve FL's robustness. Our findings establish the first systematic study of adversarial threats in PFL systems, providing both diagnostic tools and practical countermeasures.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。