arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.22593cs.LGcs.DC

GCA:联邦学习中的全局质心对齐

GCA: Global Centroid Alignment in Federated Learning

Jong-Ik Park, Harry Jiang, Logan Blakely, Georgios Fragkos, Shamina Hossain-McKenzie, Carlee Joe-Wong

AI总结:

该研究提出GCA协议,通过潜在代码介导的联邦学习,无需传输AE参数或梯度,可防御数据提取攻击,降低通信开销,提升测试准确率。

AI中文摘要:

基于自动编码器(AE)的联邦学习(FL)在客户端本地数据有限时,对异常检测颇具吸引力。然而,传统联邦学习会交换AE参数或梯度,这会产生大量通信开销,且可能暴露输入训练数据信息,因为AE被明确优化以重建其输入。我们提出了全局质心对齐(Global Centroid Alignment, GCA),一种由潜在代码介导的联邦学习协议,无需传输AE参数或梯度即可协调客户端。每轮通信中,(1)客户端先使用“重建”更新训练本地AE,并将一小部分编码器潜在代码上传至联邦学习服务器;(2)服务器汇集这些代码,拟合聚类模型,仅广播“全局潜在质心及其支持计数”;(3)每个客户端随后通过使用“逆计数”加权将其本地潜在代码与最近的质心对齐来更新编码器,以强调全球代表性不足的模式。步骤(1)至(3)在多轮通信中重复。由于GCA仅交换采样的潜在代码和质心统计数据,其通信成本取决于潜在维度、上传代码数量和返回质心数量,而非AE模型大小。在五个表格基准和两个视觉基准中,与FedAvg、FedProx和FedNova相比,在21次比较中,GCA在服务器端客户端数据提取攻击下均产生更高的重建误差,且在21次比较中的20次中余弦相似度明显更低,显示其保护训练数据的能力。它甚至比FedAvg将测试准确率提高了5.76%,达到与DP-FedAvg相当的提取防御效果,在DP-FedAvg未降低目标相似度时仍有效,且每轮通信降低了高达99.15%。

英文摘要:

Autoencoder (AE)-based federated learning (FL) is attractive for anomaly detection when clients have limited local data. However, conventional FL exchanges AE parameters or gradients, incurring substantial communication overhead and potentially exposing input training data information, since AEs are explicitly optimized to reconstruct their inputs. We introduce \emph{Global Centroid Alignment (GCA)}, a latent-code-mediated FL protocol that coordinates clients without transmitting AE parameters or gradients. In each round, (1) clients first train their local AEs using a \emph{reconstruction} update and upload a small subset of encoder latent codes to the FL server. (2) The server pools these codes, fits a clustering model, and broadcasts only \emph{global latent centroids and their support counts}. (3) Each client then updates its encoder by aligning its local latent codes with the \emph{nearest} centroid using \emph{inverse-count} weighting to emphasize globally underrepresented patterns. Steps (1)--(3) repeat over communication rounds. Because GCA exchanges only sampled latent codes and centroid statistics, its communication cost depends on latent dimensionality and the numbers of uploaded codes and returned centroids rather than on AE model size. Across five tabular and two vision benchmarks, GCA yields higher reconstruction error under a server-side client data extraction attack in all 21 comparisons and clearly lower cosine similarity in 20 of 21 comparisons with FedAvg, FedProx, and FedNova, showing its ability to protect training data. It even improves test accuracy over FedAvg by up to $5.76\%$. GCA achieves extraction defense comparable to DP-FedAvg, remains effective when DP-FedAvg does not reduce target resemblance, and lowers per-round communication by up to $99.15\%$.

↑