arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.15521cs.LG

端到端可验证且鲁棒的联邦学习

End-to-End Verifiable and Robust Federated Learning

Doryan Lesaignoux, Enrique Mármol Campos, Gabriele Spini, José L. Hernández-Ramos, Stephan Krenn

首次发表
浏览论文内容

中文总结 AI 辅助

本研究提出一种结合密码学承诺与零知识证明的联邦学习协议,实现鲁棒异常值排除与公开可验证聚合,在中毒攻击下精度损失低于4%。

中文摘要 AI 辅助

联邦学习使多方能够在聚合器的帮助下训练共享模型,而无需集中原始数据,但一旦参与者或基础设施不完全可信,就会引入完整性风险。其中两个要求尤为重要:对中毒或拜占庭客户端更新的鲁棒性,以及聚合器的可验证性,以便客户端或第三方能够在不了解个体更新的情况下审计所报告的聚合结果。现有工作大多分别处理这些目标,而针对鲁棒、排除异常值的聚合的高效公开可验证性仍然有限。我们提出了一种可验证的联邦学习协议,使鲁棒聚合流程可公开审计。我们的设计将密码学承诺与非交互式零知识证明相结合,以认证(i)基于余弦相似度的异常值排除和(ii)对选定集合的聚合,同时不向验证者泄露个体客户端更新。在代表性中毒攻击下的实验中,我们的方法保持了高精度,在评估的配置中平均精度损失低于4%,同时保持了实用的验证开销:在所研究的规模下,证明工件可以在几分钟内生成和验证。总之,我们的结果表明,在联邦学习环境中可以同时实现鲁棒的异常值排除和公开可验证性。

英文摘要

Federated learning enables multiple parties to train a shared model without centralizing raw data with the help of an aggregator, but introduces integrity risks once participants or infrastructure are not fully trustworthy. Two requirements are particularly important: robustness to poisoned or Byzantine client updates, and verifiability of the aggregator so that clients or third parties can audit the reported aggregation without learning individual updates. Existing work has largely treated these goals separately, and efficient public verifiability for robust, outlier-excluding aggregation remains limited. We present a verifiable federated learning protocol that makes a robust aggregation pipeline publicly auditable. Our design combines cryptographic commitments with non-interactive zero-knowledge proofs to certify both (i) cosine-similarity-based outlier exclusion and (ii) aggregation over the selected set, without revealing individual client updates to verifiers. In experiments under representative poisoning attacks, our method maintains high accuracy, with an average accuracy loss below 4\% across the evaluated configurations, while keeping verification overhead practical: proof artifacts can be generated and verified within minutes at the scale studied. In summary, our results show that robust outlier exclusion and public verifiability can be jointly achieved in a federated learning setting.

发表机构

  • AIT Austrian Institute of Technology(AIT奥地利技术研究所)
  • University of Murcia(穆尔西亚大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑