发表机构
Bowie State University; Télécom SudParis; Institut Polytechnique de Paris; Brown University; Northern Virginia Community College(鲍伊州立大学; 南巴黎电信学院; 巴黎综合理工学院; 布朗大学; 北弗吉尼亚社区学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出Fairis,一种协同机器学习中针对公平性投毒攻击的服务器端重加权方案,可证能约束恶意客户端权重,在台湾信用数据集上可将隐蔽对手权重降低41%-54%,优于FairFed等方法。
AI 中文摘要
金融机构间的协同机器学习必须同时具备群体公平性和针对蓄意对抗性操纵的鲁棒性。现有公平感知聚合方法在形式上仍易受公平性投毒攻击:恶意客户端在保持准确率的同时最大化群体差异,可规避基于准确率的拜占庭防御;在本文的威胁模型中,FairFed的基于差距的加权方式可被观察到全局公平性分数的对手操控。本文提出Fairis,一种服务器端重加权方案,其中每个客户端的更新获得归一化权重ωₖ = w̄ₖ / Σⱼw̄ⱼ,该权重由非归一化分数w̄ₖ = η - Fₖ构建,其中Fₖ ∈ [0,1]为本地机会均等差异,η > 1为安全参数。本文证明了三个性质:单调权重减少(MWR)、人口统计参与和非博弈性,将MWR扩展到合谋的少数派联盟,并表明将MWR与服务器端范数裁剪结合可将对手对全局模型的位移限制为ω₀C,且该位移随对手自身报告的差异严格递减。假设诚实报告分数(本文未放弃该假设),Fairis是所评估的唯一规则,可保证每个客户端获得严格正权重,同时可证地随对手的偏见单调减少其权重;裁剪后的FairFed可达到更低权重,但无任何保证,且在台湾信用数据集上会直接将某个客户端的权重归零。针对足够隐蔽以规避基于准确率的防御、且与良性模型的准确率差距在0.04以内的对手,Fairis在台湾数据集上将其权重比无大小区分的对照组降低41%至54%。在常规的非独立同分布(non-IID)划分下,没有任何规则占据主导地位;均匀加权的 ablation 实验显示,影响力约束的效果取决于对手的分数与诚实均值的偏离程度,当诚实群体本身已不公平则无效果。
英文摘要
Collaborative machine learning among financial institutions must be both group-fair and robust against deliberate adversarial manipulation. Existing fairness-aware aggregation methods remain formally vulnerable to fairness poisoning: a malicious client maximizing group disparity while preserving accuracy evades accuracy-based Byzantine defenses, and in our threat model FairFed's gap-based weighting can be gamed by an adversary who observes the global fairness score. We present Fairis, a server-side reweighting scheme in which each client's update receives the normalized weight $ω_k = \bar{w}_k / \sum_j \bar{w}_j$ built from the unnormalized score $\bar{w}_k = η- \mathcal{F}_k$, with $\mathcal{F}_k \in [0,1]$ the local Equal Opportunity Difference and $η> 1$ a security parameter. We prove three properties, Monotone Weight Reduction (MWR), Demographic Participation, and Non-Gamesmanship, extend MWR to colluding minority coalitions, and show that combining MWR with server-side norm clipping bounds the adversary's displacement of the global model by $ω_0 C$, strictly decreasing in its own reported disparity. Assuming honest score reporting, an assumption this paper does not discharge, Fairis is the only rule evaluated that guarantees every client strictly positive weight while provably reducing an adversary's weight monotonically in its bias; clipped FairFed can reach a lower weight but guarantees nothing and zeroes a client outright on Taiwan Credit. Against an adversary stealthy enough to evade accuracy-based defenses, within 0.04 accuracy of benign, Fairis cuts its weight by 41 to 54% below a size-blind control on Taiwan. On routine non-IID partitions no rule dominates, and a uniform-weighting ablation shows that containment tracks how far the adversary's score separates from the honest mean, providing none when the honest population is already unfair.
Comments37 pages, 6 figures. Extended version, adding a size-weighted variant, a clipping-based influence bound, and machine-checked proofs of the main results