arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

SWB-DM:一种带延迟动量缓存的校准切片 Wasserstein 重心聚合器,用于部分参与下的拜占庭鲁棒联邦学习

SWB-DM: A Calibrated Sliced-Wasserstein-Barycenter Aggregator with Delayed-Momentum Caching for Byzantine-Robust Federated Learning under Partial Participation

Saranraj S, Saranya M S, Alex David S, Ajay Kumar A

arXiv 2609.16099首次发表:更新:

发表机构

Vel Tech Rangarajan Dr. Sagunthala R&D Institute of Science and Technology(维尔技术兰加拉詹博士萨贡塔拉研发科技学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对联邦学习部分参与下鲁棒聚合的脆弱假设,提出 SWB-DM,结合修剪 Wasserstein 重心与延迟动量缓存,校准修剪比率,在多种攻击下展现鲁棒性优势。

AI 中文摘要

联邦学习的鲁棒聚合方法悄然依赖于一个脆弱的假设:在给定轮次中出现的客户端是全体人口的一个公平样本。在实践中,它们很少如此。当每轮只有少数客户端参与时,即使对抗者所占比例不大,也能主导该样本,并悄然使逐坐标中位数、Krum、Bulyan 和修剪均值所依赖的有限样本保证失效。我们引入 SWB-DM 来直接解决这一问题。SWB 将客户端更新的每个切片视为一维分布,计算跨客户端的修剪 Wasserstein 重心,并通过基于 medoid 的规范固定步骤恢复坐标身份——这是我们开发的一种启发式方法,并不声称它属于标准最优传输理论。DeMoA 风格的延迟动量随后在每轮中跨整个客户端群体缓存更新,将鲁棒性与实际被采样的客户端解耦。修剪比率校准并非表面功夫:在适当校准的模型能够存活的损坏水平下,修剪不足会导致崩溃。在 448 个 CIFAR-10 配置,以及 CIFAR-100、FEMNIST 和一次 500 客户端的可扩展性运行中,我们发现了多种机制上不同的失败模式。偶数样本的逐坐标中位数退化为确定性的错误答案。Krum 悄然违反其自身的 n 大于 2f+2 前提条件,并在无警告的情况下发散。Bulyan 的 n 大于或等于 4f+3 阈值产生了一个尖锐的通过/失败边界。在攻击方面,IPM 比 ALIE 更可靠地击败了包括 SWB 在内的阶统计量防御,这通过针对收敛界限的 delta 空间测量得到证实。SWB-DM 的缓存带有实际的热身成本,但将所有基线扩展到相同的轮次预算表明,其在 CIFAR-10 上的收益不成比例地大。在 CIFAR-100 上,FLTrust 受益更多——原因与缓存完全无关。

英文摘要

Robust aggregation methods for federated learning quietly rest on a fragile assumption: that whoever shows up in a given round is a fair sample of the full population. In practice, they rarely are. When only a handful of clients participate per round, even a modest fraction of adversaries can dominate that sample and silently invalidate the finite-sample guarantees that coordinate-wise median, Krum, Bulyan, and trimmed mean all depend on. We introduce SWB-DM to address this directly. SWB treats each slice of a client update as a one-dimensional distribution, computes a trimmed Wasserstein barycenter across clients, and recovers coordinate identity via a medoid-based gauge-fixing step -- a heuristic we developed and do not claim it belongs to standard optimal-transport theory. DeMoA-style delayed momentum then caches updates across the full client population each round, decoupling robustness from whoever happened to be sampled. Trim ratio calibration is not cosmetic: under-trimming causes collapse at corruption levels a properly calibrated model survives. Across 448 CIFAR-10 configurations, plus CIFAR-100, FEMNIST, and a 500-client scalability run, we find several mechanistically distinct failure modes. Even-sample coordinate-wise median degrades to a deterministic wrong answer. Krum silently violates its own n greater than 2f+2 precondition and diverges without warning. Bulyan's n greater than or equal to 4f+3 threshold produces a sharp pass/fail boundary. On attacks, IPM defeats order-statistic defenses -- including SWB -- more reliably than ALIE, confirmed through delta-space measurements against a convergence bound. SWB-DM's cache carries a real warm-up cost, but extending all baselines to the same round budget shows its CIFAR-10 gains are disproportionately large. On CIFAR-100, FLTrust benefits more -- for reasons entirely unrelated to caching.

Comments7 pages, 2 figures, 5 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑