提出鲁棒信誉机制,防止隐蔽攻击者逐步积累信任
Robust Reputation-Driven Crowdsourced Federated Learning
- 用信誉演化与邻居混合防御结合,动态过滤恶意更新
- 在对抗性攻击下表现优于现有防御方法,误报率低
- 适合关注可信联邦学习的系统设计者和安全研究者
众包联邦学习(CrowdFL)通过众包模式实现开放、异构的参与。此类场景中,信誉驱动的激励机制常被用来引导工人选择并提升可信度。然而,现有框架大多忽略其对隐蔽敌手的鲁棒性,尤其是能规避常规检测的攻击者。为此,本文提出R2CFL,一种鲁棒的信誉驱动众包联邦学习框架。R2CFL引入鲁棒信誉模型与最近邻混合(R2-NNM)防御机制,将信誉演化与聚合过程中的更新过滤相耦合,有效阻止隐蔽攻击者逐步累积信任并影响后续任务。实验表明,R2-NNM在对抗自适应攻击时表现达到或超越当前最优的拜占庭鲁棒与后门防御机制。此外,当与现有检测-过滤防御集成时,该信誉模型能准确反映底层防御的统计鲁棒性,其信誉得分紧密匹配真实阳性与阴性特征。
原文摘要 · Abstract (English)
Crowdsourced Federated Learning (CrowdFL) extends traditional federated learning by enabling open and heterogeneous participation through a crowdsourcing paradigm. In this setting, reputation-driven incentive mechanisms are commonly employed to guide worker selection and enhance trustworthiness. While such approaches improve participant reliability, existing frameworks largely overlook the quantification of their robustness against stealthy adversaries, particularly those capable of evading standard detection mechanisms. To fill this gap, this paper proposes R2CFL, a robust reputation-driven CrowdFL framework. R2CFL introduces a robust reputation model coupled with a nearest neighbor mixing (R2-NNM) defense mechanism that links reputation evolution with the filtering of updates during aggregation. The proposed mechanism prevents stealthy attackers from gradually accumulating trust and influencing future tasks. Experimental results demonstrate that R2-NNM matches or surpasses state-of-the-art Byzantine-robust and backdoor defense mechanisms against adaptive attackers. Furthermore, when integrated with existing detect-and-filter defenses, the proposed reputation model faithfully captures the statistical robustness of the underlying defense by producing reputation scores that closely reflect its true positive and false positive characteristics.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。