发表机构
University of Kentucky; University of South Florida(肯塔基大学; 南佛罗里达大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出DFL-C架构,将ACS共识协议与双域信任评分机制结合,实现拜占庭容错的全局模型一致去中心化联邦学习,在非IID场景下优于BALANCE方案。
AI 中文摘要
去中心化联邦学习(DFL)是一种极具前景的范式,可让自主节点在不依赖中央服务器的情况下协同训练AI模型。然而,现有DFL方案无法保证全局模型一致性,而这是协作关键任务场景的关键要求,模型分歧会破坏决策的一致性与安全性。这种一致性缺失还会放大对拜占庭敌手的脆弱性,敌手会利用去中心化网络拓扑与弱同步性,对单个受害者实施 equivocation(歧义性攻击)和模型投毒攻击。本文提出了DFL-C,一种新型拜占庭容错DFL架构,可让去中心化节点在全局模型一致的前提下开展协同训练。DFL-C的核心是将异步公共子集(ACS)共识协议集成到DFL工作流中,确保所有节点聚合统一的模型更新集以建立全局模型一致性,即便存在单个拜占庭歧义性攻击。DFL-C还实现了双域信任评分机制,以抵御数据域的拜占庭操纵,包括模型投毒攻击。该机制对共识协议形成补充,显著降低了后者的运行时间。实验结果表明,DFL-C在拜占庭行为下可维持模型精度并实现全局模型一致性,且共识开销适中。值得注意的是,与未提供模型一致性的最先进DFL方案BALANCE(Fang等人)相比,DFL-C在抵御非目标模型投毒攻击时实现了更优的模型精度,在抵御后门攻击时具有相当的鲁棒性,且该优势在非独立同分布(non-IID)场景下会进一步扩大。
英文摘要
Decentralized federated learning (DFL) is a promising paradigm for autonomous nodes to collaboratively train AI models without relying on a central server. However, existing DFL solutions do not guarantee global model consistency, a critical requirement for collaborative mission-critical scenarios where model divergence undermines decision uniformity and safety. This lack of consistency also amplifies vulnerability to Byzantine adversaries, who exploit the decentralized network topology and weak synchrony to perform equivocation and model poisoning attacks against individual victims. This paper introduces DFL-C, a novel Byzantine-resilient DFL architecture that enables decentralized nodes to perform collaborative training with global model consistency. At its core, DFL-C integrates an asynchronous common subset (ACS) consensus protocol into the DFL workflow to ensure all nodes aggregate a uniform set of model updates to establish global model consistency, despite individual Byzantine equivocation. DFL-C further implements a dual-domain trust scoring mechanism to provide resilience against data-domain Byzantine manipulations including model poisoning attacks. This mechanism complements the consensus protocol, significantly reducing the latter's runtime. Our experimental results demonstrate that DFL-C maintains model accuracy while achieving global model consistency under Byzantine behaviors with moderate consensus overhead. Notably, when compared with the state-of-the-art DFL solution BALANCE (Fang et al.) that does not provide model consistency, DFL-C achieves better model accuracy against untargeted model poisoning attacks and comparable resilience against backdoor attacks, with the advantage widened under non-IID scenarios.
CommentsAccepted for publication at the IEEE Conference on Communications and Network Security (CNS), 2026