针对飞机发动机健康预测,提出兼具鲁棒性与个性化的联邦学习方法。
Robust and Personalized Federated Learning for Aircraft-Engine Prognostics under Benign and Adversarial Client Heterogeneity
- 通过共享表示个性化缩小70%的本地与中心模型误差差距。
- 设计的传感器后门攻击成功率高达94.9%,但不影响正常精度。
- 结合个性化与鲁棒聚合可将攻击成功率降至2.8%,适合工业部署。
联邦学习使机队运营商可在不共享原始数据的前提下联合训练发动机剩余使用寿命(RUL)模型。本文研究两类互补挑战:良性异质性(不同运营商观测到的操作条件和故障模式差异)与恶意异质性(受损客户端提交污染更新)。在商业模块化航空推进系统仿真(C-MAPSS)基准上,采用多任务一维卷积神经网络与结构非独立同分布(non-IID)划分进行受控、安全评估。对比四种缓解良性异质性的方法,并评估五种攻击对四种聚合策略的影响,包括一种基于物理机制的传感器值后门,用于隐藏发动机退化。共享表示个性化将本地与中心模型的均方根误差差距缩小约70%,优于近端正则化(21%)与服务器重加权(10%)。后门攻击在标准平均下成功率达94.9%,且干净精度无显著变化,表明仅凭准确率无法保证模型安全,必须显式评估攻击成功率。Krum将攻击成功率降低一个数量级,是唯一能抵御协同攻击的聚合器;而个性化本身无法提供防护。将个性化与鲁棒聚合结合,可恢复鲁棒性(攻击成功率2.8%),仅带来小幅精度损失,揭示了鲁棒更新选择与协作表征学习间的权衡。结果在不同客户端数量及更难的六工况数据集上保持一致。代码与数据划分已开源以确保可复现性。
原文摘要 · Abstract (English)
Federated learning (FL) enables aircraft fleet operators to jointly train remaining-useful-life (RUL) models from engine sensor telemetry without sharing raw data. This study examines two complementary challenges: benign heterogeneity, where honest operators observe different operating conditions and fault modes, and adversarial heterogeneity, where compromised operators submit poisoned updates. We conduct a controlled, safety-oriented evaluation using a multi-task one-dimensional convolutional neural network and a structurally non-IID partition of the Commercial Modular Aero-Propulsion System Simulation (C-MAPSS) benchmark. We compare four remedies for benign heterogeneity and evaluate five attacks against four aggregation methods, including a physically motivated sensor-value backdoor designed to mask engine degradation. Shared-representation personalization closes approximately 70% of the local-to-centralized root-mean-square-error gap, compared with 21% for proximal regularization and 10% for server-side reweighting. The backdoor achieves a 94.9% attack success rate against standard averaging while leaving clean accuracy statistically unchanged, demonstrating that accuracy alone cannot certify model safety and that attack success must be evaluated explicitly. Krum reduces attack success by an order of magnitude and is the only evaluated aggregator that withstands coordinated attackers, whereas personalization alone provides no protection. Combining personalization with robust aggregation restores robustness (2.8% attack success) with only a small accuracy cost, revealing a trade-off between robust update selection and collaborative representation learning. Results remain consistent across client counts and on a harder six-condition dataset. Code and data partitions are released for reproducibility.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。