arXiv:2607.10970cs.LG2026-07

提出截断二次损失提升异构数据下联邦学习抗恶意攻击能力

Enhanced Byzantine-Robust Federated Learning Via Truncated-Quadratic Loss for Heterogeneous Data

  • 用截断二次损失替代传统聚合方法,缓解异常值偏差
  • 在非凸损失和高异构数据下实现近最优鲁棒性,实验验证更优
  • 仅需估计恶意客户端数量即可保持鲁棒,适合真实分布式场景

联邦学习将数据分布于n个客户端,易受恶意攻击和数据异构性影响。现有中心裁剪与Huber聚合器虽用于抗拜占庭攻击,但通过凸共轭理论证明二者等价,且在存在异常值时会产生偏差,导致在高异构数据和大量异常客户端下失效。本文提出一种基于截断二次(TQ)损失的新聚合规则,有效缓解此类偏差。理论证明该方法在非凸损失函数和异构数据下可实现阶最优的拜占庭鲁棒性,显著提升系统可靠性。此外,提出TQ的鲁棒偏差估计策略并验证其有效性;即使仅知恶意客户端数量的估计值,仍能保持鲁棒性。在MNIST、Fashion-MNIST和CIFAR-10上的实验表明,所提方法优于现有技术。

原文摘要 · Abstract (English)

Federated learning distributes data among $n$ clients, making it vulnerable to malicious attacks and data heterogeneity, which together pose challenges for robust learning. To tackle this issue, centered clipping and Huber aggregators have been exploited for Byzantine robustness. In this paper, we first demonstrate their equivalence via convex conjugate theory, and show that they can yield biased solutions in the presence of outliers, leading to failure under high data heterogeneity and a substantial fraction of outliers. Next, we propose a new robust aggregation rule that utilizes the truncated-quadratic (TQ) loss, effectively mitigating the biases of existing methods, such as centered clipping and Huber aggregators. We show that our aggregator achieves order-optimal Byzantine-robust learning under nonconvex loss functions and heterogeneous data, ultimately enhancing the reliability of federated learning systems. Additionally, we provide a robust deviation estimation strategy for TQ, demonstrating its effectiveness. Furthermore, we show that TQ maintains robustness even when only an estimate of the number of Byzantine clients is available. Finally, experimental results on MNIST, Fashion-MNIST, and CIFAR-10, indicate that our aggregator provides better robustness performance than the competing techniques.

联邦学习鲁棒聚合异构数据拜占庭攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。