AI 中文总结
针对对抗环境下动态去中心化联邦学习的拓扑操纵与模型投毒问题,提出DMTT协议,结合证据深度学习与Beta分布信任模型,在UCI HAR和PAMAP2数据集上实现优于对比方法的鲁棒性能。
AI 中文摘要
在动态移动去中心化联邦学习(DFL)中,攻击者可同时投毒模型更新和设备用于选择协作方的拓扑信息。我们提出DMTT(Dynamic MURMURA with Trusted Topology,带可信拓扑的动态MURMURA),这是一种基于MURMURA构建的去中心化个性化联邦学习(FL)协议,它采用证据深度学习对分布不匹配的节点进行降权,扩展至应对拓扑操纵攻击下的时变图场景。每个设备通过链路可靠性估计、签名拓扑声明、见证佐证以及Beta分布的源信任模型,维护置信度加权的本地拓扑视图,随后仅在经信任筛选的协作方集合上进行聚合,该集合采用融合模型兼容性、拓扑信任和链路可靠性的综合评分。我们证明,经筛选的混合矩阵可将拜占庭影响限制在有界残差δ_max内,当筛选完美时该残差消失;并将DMTT实现为无协调器的分布式系统,每个客户端作为独立的ZeroMQ进程运行,通过共享的 wall-clock 周期同步。在UCI HAR和PAMAP2数据集上,两个数据集均按Dirichlet异质性划分为100个移动客户端,DMTT在所有测试的攻击比例(10%至80%)下,诚实节点准确率维持在0.862(UCI HAR)和0.829(PAMAP2)以上,低攻击比例时几乎与无攻击准确率相当,极端比例时则平稳退化为仅本地性能;静态和动态FedAvg在所有比例下均降至随机水平,而鲁棒聚合器(Krum、BALANCE、UBAR)无法始终优于仅本地基线,DMTT是唯一在两个数据集所有比例下均达到该基线的方法,且拜占庭聚合权重经验上始终为零,与δ_max=0一致。该协议通过墨尔本研究云上的无协调器ZeroMQ后端在真实节点上运行端到端流程。
英文摘要
In dynamic mobile decentralized federated learning (DFL), adversaries can poison both model updates and the topology information devices use to choose collaborators. We present DMTT (Dynamic MURMURA with Trusted Topology), a decentralized personalized FL protocol built on MURMURA, which uses evidential deep learning to down-weight distribution-mismatched peers, extended here to time-varying graphs under topology-manipulation attacks. Each device maintains a confidence-weighted local topology view from link-reliability estimates, signed topology claims, witness corroboration, and a Beta-distributed source-trust model, then aggregates only over a trust-screened collaborator set using a composite score fusing model compatibility, topology trust, and link reliability. We prove the screened mixing matrices confine Byzantine influence to a bounded residual $δ_{max}$ that vanishes under perfect screening, and implement DMTT as a coordinator-free distributed system with each client running as an independent ZeroMQ process synchronized by a shared wall-clock epoch. On UCI HAR and PAMAP2, each partitioned across 100 mobile clients with Dirichlet heterogeneity, DMTT sustains honest-node accuracy above 0.862 (UCI HAR) and 0.829 (PAMAP2) across all tested adversary fractions (10 to 80%), nearly matching no-attack accuracy at low fractions and degrading gracefully toward local-only performance at extremes; static and dynamic FedAvg collapse to chance at every fraction, and robust aggregators (Krum, BALANCE, UBAR) fail to consistently beat a local-only baseline, while DMTT is the only method that clears this bar across both datasets at all fractions, with surviving Byzantine aggregation weight empirically zero throughout, consistent with $δ_{max}$=0. The protocol runs end-to-end on real nodes via a coordinator-free ZeroMQ backend on the Melbourne Research Cloud.