arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CARVY-FL:可证明安全联邦学习中用于鲁棒投票的客户端反聚类

CARVY-FL: Client Anticlustering for Robust Voting in Provably Secure Federated Learning

Masaki Nakada, Honoka Anada, Tatsuya Kaneko, Hiroshi Nakamura, Shinya Takamaeda-Yamazaki, Hideki Takase

arXiv 2608.28992首次发表:更新:

发表机构

The University of Tokyo; Institute of Science Tokyo; RIKEN(东京大学; 东京科学大学; 理化学研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对联邦学习中基于投票的方法在非IID数据下认证准确率波动大的问题,提出CARVY-FL,通过客户端分布类型估计与反聚类提升投票鲁棒性,在多个数据集及攻击场景下均取得优于FLCert的性能。

AI 中文摘要

联邦学习(FL)支持协作训练且无需直接共享原始数据,但仍易受恶意客户端攻击。基于投票的FL通过将客户端划分为组、每组训练一个模型并以多数投票聚合预测来提升鲁棒性。然而在类别不相交的非独立同分布(non-IID)数据下,与分布无关的分组会导致认证准确率(CA)波动极大。我们提出CARVY-FL,该方法从单轮模型更新中估计客户端分布类型,并采用反聚类来增加组内分布多样性。在固定分组下,CARVY-FL保留基于投票的CA保证同时提升投票 margin。在MNIST和Fashion-MNIST上的实验显示其CA优于FLCert;在含模型替换的BadNets攻击下,CARVY-FL使100-ASR的AUC分别提升11.1%和14.9%。

英文摘要

Federated learning (FL) enables collaborative training without directly sharing raw data, but remains vulnerable to malicious clients. Voting-based FL improves robustness by partitioning clients into groups, training one model per group, and aggregating predictions by plurality voting. However, under class-disjoint non-IID data, distribution-oblivious grouping can yield highly variable certified accuracy (CA). We propose CARVY-FL, which estimates client distribution types from one-epoch model updates and uses anticlustering to increase within-group distributional diversity. Under a fixed grouping, CARVY-FL retains the voting-based CA guarantee while increasing vote margins. Experiments on MNIST and Fashion-MNIST show higher CA than FLCert. Under BadNets with model replacement, CARVY-FL improves the AUC of 100-ASR by 11.1% and 14.9%, respectively.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑