FL-OA:面向智能设备的带外包审计的拜占庭鲁棒联邦学习框架
FL-OA: A Byzantine-Robust Federated Learning Framework with Outsourced Auditing for Intelligent Devices
浏览论文内容
中文总结 AI 辅助
针对联邦学习易受拜占庭攻击且现有防御方法存在局限的问题,提出带外包审计的FL-OA框架,通过第三方审计、梯度上升与参数重要性指标等技术,提升鲁棒性并缓解维度灾难,实验验证其性能优于现有方法。
中文摘要 AI 辅助
联邦学习(FL)允许多个智能设备在不共享原始数据的情况下协同训练高精度模型,但由于其分布式特性,易受拜占庭攻击。现有防御方法依赖强假设,如恶意设备占比不超过50%,或服务器拥有与训练任务匹配的额外根数据集,且因忽略良性更新间的分歧及比较高维更新时的维度灾难,效果有限。为解决这些问题,我们提出FL-OA,一种带外包审计的拜占庭鲁棒联邦学习框架。在FL-OA中,服务器与持有额外根数据集的第三方机构协作执行外包审计,无需强假设即可实现鲁棒聚合;此外,FL-OA在本地训练中引入梯度上升步骤和修正项以缓解良性更新间的分歧,并设计参数重要性指标提取关键参数用于审计,缓解维度灾难。我们还提供了FL-OA的详细理论分析,大量实验表明,FL-OA在抵御拜占庭攻击方面优于现有防御方法。
英文摘要
Federated learning (FL) enables multiple intelligent devices to collaboratively train a high-accuracy model without sharing raw data. However, due to its distributed nature, FL is vulnerable to Byzantine attacks. Existing defense methods rely on strong assumptions, such as the proportion of malicious devices not exceeding 50\%, or the server having an additional root dataset that matches the training task. Moreover, they show limited efficacy as they overlook $(i)$ the divergence among benign updates and $(ii)$ the curse of dimensionality involved in comparing two high-dimensional updates. To solve these concerns, we propose FL-OA, a Byzantine-robust federated learning framework utilizing outsourced auditing. In FL-OA, the server collaborates with third-party organization that holds an additional root dataset to perform outsourced auditing, thereby enabling the server to achieve robust aggregation without strong assumptions. Additionally, FL-OA introduces a gradient ascent step and a correction term during local training to mitigate the divergence among benign updates, and designs a parameter importance indicator to extract critical parameters for auditing, alleviating the curse of dimensionality. We further provide a detailed theoretical analysis of FL-OA. Extensive experiments demonstrate that FL-OA outperforms existing defense methods against Byzantine attacks.