发表机构
Rajshahi University of Engineering & Technology; North South University; Missouri State University; Malardalen University; American International University-Bangladesh(拉杰沙希工程与技术大学; 北南大学; 密苏里州立大学; 梅拉达伦大学; 孟加拉国美国国际大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究针对飞机发动机预测场景,在良性与对抗性客户端异质性下,结合个性化与鲁棒聚合的联邦学习方法,可在保证预测性能的同时抵御攻击,相关代码与数据划分已公开。
AI 中文摘要
联邦学习(FL)使机队运营商能够在不共享原始数据的情况下,利用发动机传感器遥测数据联合训练剩余使用寿命(RUL)模型。本研究探讨两个互补挑战:良性异质性(诚实运营商观测到不同的运行工况和故障模式)与对抗性异质性(受攻击的运营商提交中毒更新)。我们采用多任务一维卷积神经网络,并对商用模块化航空推进系统仿真(C-MAPSS)基准进行结构非独立同分布(non-IID)划分,开展受控的安全导向评估。我们对比了四种针对良性异质性的解决方案,并评估了五种攻击对四种聚合方法的效果,其中包括一种旨在掩盖发动机退化的、基于物理原理的传感器值后门攻击。共享表示个性化方法可缩小约70%的本地到集中式均方根误差(RMSE)差距,而近端正则化和服务器端重加权分别仅缩小21%和10%。该后门攻击对标准平均聚合的攻击成功率达94.9%,同时保持干净数据的准确率在统计上无变化,表明仅靠准确率无法验证模型安全性,必须明确评估攻击成功率。Krum可将攻击成功率降低一个数量级,是唯一能抵御协同攻击者的评估聚合方法,而仅靠个性化无法提供保护。将个性化与鲁棒聚合相结合可恢复鲁棒性(攻击成功率为2.8%),仅伴随微小的准确率损失,揭示了鲁棒更新选择与协作表示学习之间的权衡关系。结果在不同客户端数量及更难的六工况数据集上均保持一致,代码与数据划分已公开以支持可复现性。
英文摘要
Federated learning (FL) enables aircraft fleet operators to jointly train remaining-useful-life (RUL) models from engine sensor telemetry without sharing raw data. This study examines two complementary challenges: benign heterogeneity, where honest operators observe different operating conditions and fault modes, and adversarial heterogeneity, where compromised operators submit poisoned updates. We conduct a controlled, safety-oriented evaluation using a multi-task one-dimensional convolutional neural network and a structurally non-IID partition of the Commercial Modular Aero-Propulsion System Simulation (C-MAPSS) benchmark. We compare four remedies for benign heterogeneity and evaluate five attacks against four aggregation methods, including a physically motivated sensor-value backdoor designed to mask engine degradation. Shared-representation personalization closes approximately 70% of the local-to-centralized root-mean-square-error gap, compared with 21% for proximal regularization and 10% for server-side reweighting. The backdoor achieves a 94.9% attack success rate against standard averaging while leaving clean accuracy statistically unchanged, demonstrating that accuracy alone cannot certify model safety and that attack success must be evaluated explicitly. Krum reduces attack success by an order of magnitude and is the only evaluated aggregator that withstands coordinated attackers, whereas personalization alone provides no protection. Combining personalization with robust aggregation restores robustness (2.8% attack success) with only a small accuracy cost, revealing a trade-off between robust update selection and collaborative representation learning. Results remain consistent across client counts and on a harder six-condition dataset. Code and data partitions are released for reproducibility.