arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.03064cs.CRcs.LG

差分隐私联邦学习与拜占庭鲁棒聚合:面向银行与医疗系统安全模型训练的跨域框架

Differentially private federated learning with Byzantine-robust aggregation: A cross-domain framework for secure model training in banking and healthcare systems

Srikumar Nayak

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出DP-BR-FedAvg框架,结合差分隐私与拜占庭鲁棒聚合,在跨机构分类任务中平衡隐私保护与模型鲁棒性,解决联邦学习的隐私泄露和恶意更新问题。

中文摘要 AI 辅助

联邦学习允许银行、医院及其他受监管机构在不将原始记录移出自身服务器的情况下训练共享模型,这在数据保护法或竞争敏感性规则禁止集中汇聚数据的场景中极具吸引力。实际应用中,该承诺的可信性受两个问题限制:其一,客户端交换的参数更新仍会通过梯度反转和成员推理攻击泄露本地记录信息;其二,FedAvg这类诚实平均规则无法防御提交损坏或对抗性更新的客户端子集,少量恶意或被入侵的参与者可悄悄引导共享模型偏离正轨。本文提出联邦学习框架DP-BR-FedAvg,将高斯机制差分隐私层与逐坐标修剪均值拜占庭鲁棒聚合规则结合,在类似欺诈和临床风险评分的模拟跨机构分类任务上评估。在60轮通信、20个客户端(其中四分之一为拜占庭客户端)的设置下,普通FedAvg在少数类上崩溃(F1分数0.030),而所提框架恢复了更多信号(F1分数0.119),同时限制了任何单个客户端贡献的隐私损失。不含隐私层的拜占庭鲁棒聚合器在原始准确率上表现最佳,量化了隐私对鲁棒性的成本。结果表明,隐私与鲁棒性机制相互作用而非简单叠加,受监管、对抗性、跨机构场景的系统设计需考虑这种交互作用。

英文摘要

Federated learning allows banks, hospitals, and other regulated organizations to train a shared model without moving raw records off their own servers, which is attractive wherever data protection law or competitive sensitivity rules out pooling data centrally. Two problems limit how far this promise can be trusted in practice. First, the parameter updates that clients exchange still leak information about local records through gradient inversion and membership inference attacks. Second, an honest averaging rule such as FedAvg has no defense against a subset of clients that submit corrupted or adversarial updates, so a small number of malicious or compromised participants can quietly steer the shared model off course. This paper presents a federated learning framework, DP-BR-FedAvg, that combines a Gaussian-mechanism differential privacy layer with a coordinate-wise trimmed-mean Byzantine-robust aggregation rule, evaluated on a simulated cross-institutional classification task resembling fraud and clinical-risk scoring. Across sixty communication rounds with twenty clients, a quarter of them Byzantine, plain FedAvg collapses on the minority class (F1-score 0.030) while the proposed framework recovers substantially more of the signal (F1-score 0.119) while bounding the privacy loss of any single client's contribution. A Byzantine-robust aggregator with no privacy layer performs best in raw accuracy, quantifying the cost privacy imposes on robustness. The results show that privacy and robustness mechanisms interact rather than simply add, and that system design for regulated, adversarial, cross-institutional settings needs to budget for that interaction.

发表机构

  • LTIMindtree Research(LTIMindtree研究院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑