提出可外包审计的抗拜占庭联邦学习框架,无需强假设即可防御恶意攻击。
FL-OA: A Byzantine-Robust Federated Learning Framework with Outsourced Auditing for Intelligent Devices

- 引入第三方审计机构与根数据集,实现无强假设的鲁棒聚合。
- 通过梯度上升和参数重要性筛选,缓解良性更新偏差并降低维度挑战。
- 适合智能设备协同训练场景,尤其在高维模型中表现更优。
联邦学习(FL)允许多个智能设备在不共享原始数据的情况下协同训练高精度模型。然而,由于其分布式特性,FL易受拜占庭攻击影响。现有防御方法依赖于强假设,如恶意设备比例不超过50%,或服务器拥有与训练任务匹配的额外根数据集。此外,这些方法因忽略(i)良性更新间的差异性,以及(ii)高维更新比较带来的维度灾难问题,效果有限。为此,本文提出FL-OA,一种利用外包审计的拜占庭鲁棒联邦学习框架。在该框架中,服务器与持有额外根数据集的第三方机构合作进行外包审计,使服务器能在无强假设下实现鲁棒聚合。同时,FL-OA在本地训练中引入梯度上升步骤和修正项,以缓解良性更新间的差异;设计参数重要性指示器,提取关键参数用于审计,从而缓解维度灾难。我们进一步提供了FL-OA的详细理论分析。大量实验表明,FL-OA在对抗拜占庭攻击方面优于现有防御方法。
原文摘要 · Abstract (English)
Federated learning (FL) enables multiple intelligent devices to collaboratively train a high-accuracy model without sharing raw data. However, due to its distributed nature, FL is vulnerable to Byzantine attacks. Existing defense methods rely on strong assumptions, such as the proportion of malicious devices not exceeding 50\%, or the server having an additional root dataset that matches the training task. Moreover, they show limited efficacy as they overlook $(i)$ the divergence among benign updates and $(ii)$ the curse of dimensionality involved in comparing two high-dimensional updates. To solve these concerns, we propose FL-OA, a Byzantine-robust federated learning framework utilizing outsourced auditing. In FL-OA, the server collaborates with third-party organization that holds an additional root dataset to perform outsourced auditing, thereby enabling the server to achieve robust aggregation without strong assumptions. Additionally, FL-OA introduces a gradient ascent step and a correction term during local training to mitigate the divergence among benign updates, and designs a parameter importance indicator to extract critical parameters for auditing, alleviating the curse of dimensionality. We further provide a detailed theoretical analysis of FL-OA. Extensive experiments demonstrate that FL-OA outperforms existing defense methods against Byzantine attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。