arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.08574cs.LGcs.CRcs.DC

鲁棒性声誉驱动的众包联邦学习

Robust Reputation-Driven Crowdsourced Federated Learning

Mouhamed Amine Bouchiha, Gregory Blanc

首次发表
浏览论文内容

中文总结 AI 辅助

针对现有声誉驱动众包联邦学习框架忽视对隐蔽攻击者鲁棒性量化的问题,提出R2CFL框架,其R2-NNM防御机制可阻止攻击者积累信任,实验显示其防御性能优于或媲美现有先进防御机制,且可与现有防御结合提升鲁棒性。

中文摘要 AI 辅助

众包联邦学习(Crowdsourced Federated Learning, CrowdFL)通过众包范式实现开放异构参与,扩展了传统联邦学习。在此场景中,声誉驱动的激励机制常被用于引导工作者选择并提升可信度。尽管此类方法能提高参与者可靠性,但现有框架大多忽视了其对隐蔽攻击者的鲁棒性量化,尤其是那些能够规避标准检测机制的攻击者。为填补这一空白,本文提出R2CFL,一种鲁棒性声誉驱动的CrowdFL框架。R2CFL引入鲁棒声誉模型,结合近邻混合(R2-NNM)防御机制,将声誉演化与聚合过程中的更新过滤关联起来。该机制可阻止隐蔽攻击者逐步积累信任并影响后续任务。实验结果表明,针对自适应攻击者,R2-NNM的性能与最先进的拜占庭鲁棒防御机制及后门防御机制相当或更优。此外,当与现有的检测-过滤防御机制结合时,所提声誉模型通过生成能准确反映其真阳性和假阳性特征的声誉分数,忠实地捕捉了底层防御的统计鲁棒性。

英文摘要

Crowdsourced Federated Learning (CrowdFL) extends traditional federated learning by enabling open and heterogeneous participation through a crowdsourcing paradigm. In this setting, reputation-driven incentive mechanisms are commonly employed to guide worker selection and enhance trustworthiness. While such approaches improve participant reliability, existing frameworks largely overlook the quantification of their robustness against stealthy adversaries, particularly those capable of evading standard detection mechanisms. To fill this gap, this paper proposes R2CFL, a robust reputation-driven CrowdFL framework. R2CFL introduces a robust reputation model coupled with a nearest neighbor mixing (R2-NNM) defense mechanism that links reputation evolution with the filtering of updates during aggregation. The proposed mechanism prevents stealthy attackers from gradually accumulating trust and influencing future tasks. Experimental results demonstrate that R2-NNM matches or surpasses state-of-the-art Byzantine-robust and backdoor defense mechanisms against adaptive attackers. Furthermore, when integrated with existing detect-and-filter defenses, the proposed reputation model faithfully captures the statistical robustness of the underlying defense by producing reputation scores that closely reflect its true positive and false positive characteristics.

发表机构

  • Télécom SudParis(南巴黎电信学院)
  • Institut Polytechnique de Paris(巴黎综合理工学院)
  • SAMOVAR(萨莫瓦尔实验室)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑