arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

优化去中心化联邦学习中的拜占庭节点放置

Optimizing Byzantine Node Placement in Decentralized Federated Learning

Edoardo Gabrielli, Gabriele Tolomei

arXiv 2609.01495首次发表:更新:

发表机构

Sapienza University of Rome(罗马大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对去中心化联邦学习(DFL)中拜占庭节点放置被忽视的问题,提出拜占庭放置影响力(BPI)度量并开发优化算法,经实验验证其能有效识别高破坏性配置,是DFL鲁棒性评估的关键维度。

AI 中文摘要

去中心化联邦学习(DFL)的安全评估通常聚焦于拜占庭参与者的行为,却在很大程度上忽略了哪些参与者被攻陷。然而,由于聚合是在通信图上分布式进行的,拜占庭节点的放置决定了恶意影响如何在网络中传播。因此,我们将拜占庭放置视为明确的对抗性决策,在固定的攻陷预算下,将攻击者的目标表述为选择一组参与者,使其对诚实节点的有限时间影响最大化。为了在不针对每个候选放置执行学习过程的情况下近似该目标,我们引入了拜占庭放置影响力(BPI),这是一种源自实际闲聊动态的集合级度量,用于量化训练周期内诚实节点对拜占庭源的累积暴露。与基于节点中心性启发式的放置准则不同,BPI直接考虑了加权多跳传播以及被攻陷节点之间的相互作用。我们开发了优化BPI的高效算法,并在六种异构图族、非针对性模型投毒和后门攻击场景中对其进行评估。BPI引导的放置在不同网络结构中始终能识别出极具破坏性的配置,且在通过拜占庭鲁棒聚合放松线性闲聊假设时仍保持有效。我们的结果表明,拜占庭放置是DFL威胁模型和鲁棒性评估中一个关键但未充分建模的维度。

英文摘要

Security evaluations of decentralized federated learning (DFL) typically focus on how Byzantine participants behave, while largely overlooking which participants are compromised. Yet, because aggregation is distributed over a communication graph, the placement of Byzantine nodes determines how malicious influence propagates through the network. We therefore treat Byzantine placement as an explicit adversarial decision and formulate the attacker's objective as selecting, under a fixed compromise budget, the set of participants that maximizes its finite-time impact on honest nodes. To approximate this objective without executing the learning process for every candidate placement, we introduce Byzantine Placement Influence (BPI), a set-level measure derived from the actual gossip dynamics that quantifies the cumulative exposure of honest nodes to Byzantine sources over the training horizon. Unlike placement criteria based on node centrality heuristics, BPI directly accounts for weighted multi-hop propagation and interactions among compromised nodes. We develop efficient algorithms for optimizing BPI and evaluate them across six heterogeneous graph families, untargeted model poisoning, and backdoor attacks. BPI-guided placements consistently identify highly damaging configurations across different network structures and remain effective when the linear gossip assumption is relaxed through Byzantine-robust aggregation. Our results show that Byzantine placement is a critical but under-modeled dimension of DFL threat models and robustness evaluations.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑