发表机构
The University of Tokyo; Institute of Science Tokyo; RIKEN(东京大学; 东京科学大学; 理化学研究所)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对联邦学习中基于投票的方法在非IID数据下认证准确率波动大的问题,提出CARVY-FL,通过客户端分布类型估计与反聚类提升投票鲁棒性,在多个数据集及攻击场景下均取得优于FLCert的性能。
AI 中文摘要
联邦学习(FL)支持协作训练且无需直接共享原始数据,但仍易受恶意客户端攻击。基于投票的FL通过将客户端划分为组、每组训练一个模型并以多数投票聚合预测来提升鲁棒性。然而在类别不相交的非独立同分布(non-IID)数据下,与分布无关的分组会导致认证准确率(CA)波动极大。我们提出CARVY-FL,该方法从单轮模型更新中估计客户端分布类型,并采用反聚类来增加组内分布多样性。在固定分组下,CARVY-FL保留基于投票的CA保证同时提升投票 margin。在MNIST和Fashion-MNIST上的实验显示其CA优于FLCert;在含模型替换的BadNets攻击下,CARVY-FL使100-ASR的AUC分别提升11.1%和14.9%。
英文摘要
Federated learning (FL) enables collaborative training without directly sharing raw data, but remains vulnerable to malicious clients. Voting-based FL improves robustness by partitioning clients into groups, training one model per group, and aggregating predictions by plurality voting. However, under class-disjoint non-IID data, distribution-oblivious grouping can yield highly variable certified accuracy (CA). We propose CARVY-FL, which estimates client distribution types from one-epoch model updates and uses anticlustering to increase within-group distributional diversity. Under a fixed grouping, CARVY-FL retains the voting-based CA guarantee while increasing vote margins. Experiments on MNIST and Fashion-MNIST show higher CA than FLCert. Under BadNets with model replacement, CARVY-FL improves the AUC of 100-ASR by 11.1% and 14.9%, respectively.