arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.16373cs.LG

单次联邦贝叶斯模型中通过后验事件传输的认证不确定性传播

Certified Uncertainty Propagation in One-Shot Federated Bayesian Models via Posterior Event Transport

Mahyar Mohammadi, Mohammad Hossein Badiei, Abolfazl Yaghmaei, Hamed Kebriaei

首次发表
浏览论文内容

中文总结 AI 辅助

针对单次联邦贝叶斯模型,提出通过后验事件传输的部署一致认证框架,精确刻画FedAvg聚合下的安全概率下界,实验显示传输认证与直接全局认证存在显著差异。

中文摘要 AI 辅助

贝叶斯神经网络的概率认证对模型满足验证器定义的安全属性的后验概率进行下界估计。然而,在单次联邦贝叶斯学习中,部署的模型是通过聚合来自各客户端特定后验分布的参数获得的,因此局部认证并不能直接保证聚合模型的安全性。本文通过部署聚合规则传播局部后验事件,开发了一个部署一致的认证框架,并对联邦平均(FedAvg)给出了精确的几何刻画。每个客户端在参数空间中构建不相交的超矩形区域,并计算其概率质量。服务器形成这些区域的笛卡尔积,通过部署规则映射它们,并且仅当聚合图像被验证满足安全属性时保留一个乘积事件。在客户端后验独立的情况下,每个乘积事件的概率可分解为局部质量的乘积,将已验证的不相交事件求和即可得到部署模型安全概率的下界。对于具有非负聚合系数的FedAvg,轴对齐超矩形笛卡尔积的图像恰好是一个加权超矩形,不引入集合过近似。我们将所提出的传输事件认证与FedAvg和高斯积聚合诱导的后验分布下的直接认证区分开来。在标签狄利克雷异质性下的MNIST和Fashion-MNIST实验表明,传输的FedAvg认证范围从22.51%到46.89%,而直接全局认证范围从72.05%到91.39%。结果表明,预测准确性和可认证安全性不一定遵循相同的趋势,并且全局后验构造在不同架构上可能表现出不同的认证行为。

英文摘要

Probabilistic certification of Bayesian neural networks lower-bounds the posterior probability that a model satisfies a verifier-defined safety property. In one-shot federated Bayesian learning, however, the deployed model is obtained by aggregating parameters drawn from client-specific posterior distributions, so local certificates do not directly guarantee safety of the aggregated model. This paper develops a deployment-consistent certification framework by propagating local posterior events through the deployment aggregation rule, with an exact geometric characterization for Federated Averaging (FedAvg). Each client constructs disjoint hyper-rectangular regions in parameter space and computes their probability masses. The server forms Cartesian products of these regions, maps them through the deployment rule, and retains a product event only when its aggregation image is verified to satisfy the safety property. Under independent client posteriors, each product-event probability factorizes into local masses, and summing verified disjoint events yields a lower bound on safety probability of the deployed model. For FedAvg with nonnegative aggregation coefficients, the image of a Cartesian product of axis-aligned hyper-rectangles is exactly a weighted hyper-rectangle, introducing no set over-approximation. We distinguish the proposed transported-event certificate from direct certification under posterior distributions induced by FedAvg and Product-of-Gaussians aggregation. Experiments on MNIST and Fashion-MNIST under label-Dirichlet heterogeneity show that the transported FedAvg certificate ranges from 22.51% to 46.89%, while direct global certificates range from 72.05% to 91.39%. Results show that predictive accuracy and certifiable safety do not necessarily follow the same trend, and that global posterior constructions can exhibit distinct certification behavior across architectures.

发表机构

  • University of Tehran(德黑兰大学)
  • Institute for Research in Fundamental Sciences (IPM)(基础科学研究所(IPM))

机构由 AI 辅助整理,请以论文原文为准。

↑