arXiv:2608.07274cs.LGcs.AI2026-08

针对分割联邦学习的中毒攻击,提出特征解耦防御框架。

TOFD: Target-Oriented Feature Decoupling against Poisoning Attacks in Split Federated Learning

论文配图:TOFD: Target-Oriented Feature Decoupling against Poisoning Attacks in Split Federated Learning
图 1 · 摘自论文原文
  • 通过目标感知特征解耦,分三阶段检测并净化恶意数据。
  • 在五个数据集上均显著优于现有方法,且计算开销低。
  • 适合注重隐私与安全的边缘设备联邦学习场景。

分割联邦学习(SFL)在降低客户端负担的同时实现隐私保护协作训练,但其分层架构带来了独特的攻击面,易受多种中毒攻击。现有防御手段多未利用分层特性,难以早期发现并遏制恶意行为。为此,我们提出目标导向特征解耦(TOFD)框架,实现对多种中毒攻击的主动检测与鲁棒优化。TOFD包含三个阶段:(1) 目标推断,通过类特定边际扰动(MP)细化类别安全区域以识别潜在攻击目标;(2) 样本净化,基于跨类极值归一化校准阈值,自适应过滤被篡改的数据;(3) 解耦优化,利用对抗引导模型捕捉攻击引发的模式,在优化中解耦其影响,抑制残留对抗效应。我们提供了TOFD收敛性的理论保证。在五个数据集上的大量实验表明,TOFD在多种攻击场景下持续优于最先进防御方法,兼具优异鲁棒性与低计算开销,适用于实际部署。

原文摘要 · Abstract (English)

Split Federated Learning (SFL) facilitates privacy-preserving collaborative training with reduced client-side overhead. However, its split architecture introduces unique attack surfaces, rendering it vulnerable to diverse poisoning attacks. Most existing defenses fail to exploit the split paradigm, limiting their ability to detect and contain malicious behaviors at an early stage. To bridge this gap, we propose Target-Oriented Feature Decoupling (TOFD), a unified framework that jointly enables proactive detection and robust optimization against a wide range of poisoning attacks. TOFD operates in three stages: (1) Target Inference, which identifies potential attack targets by refining class-wise safe zones via class-specific Margin Perturbation (MP); (2) Sample Purification, which adaptively filters poisoned smashed data using thresholds calibrated through cross-class min-max normalization of MP; and (3) Decoupling Optimization, which leverages an adversarial guidance model to capture attack-induced patterns and decouple their influence during optimization, thereby suppressing residual adversarial effects. We provide theoretical guarantees for the convergence of TOFD. Extensive experiments on five datasets demonstrate that TOFD consistently outperforms state-of-the-art defenses under diverse attack scenarios, achieving superior robustness with low computational overhead suitable for practical deployment.

联邦学习安全防御中毒攻击特征解耦

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。