arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

OPFL:通过经验边界对联邦学习进行乐观验证

OPFL: Optimistic Verification of Federated Learning via Empirical Boundary

Hongxu Su, Jianzhu Yao, Xuechao Wang, Pramod Viswanath

arXiv 2609.37011首次发表:更新:

AI 中文总结

OPFL提出一种基于经验边界的乐观验证框架,在MPC中重放客户端训练以检测恶意更新,通过校准边界区分良性偏差与攻击,实验显示对投毒攻击实现0% ASR,且显著降低验证开销。

AI 中文摘要

联邦学习使多个客户端能够在无需共享私有数据的情况下协作训练模型。然而,由于缺乏对本地训练的可见性,难以验证客户端是否遵循规定的训练流程,或是否提交恶意更新(如模型投毒)。一种自然的方法是通过重放客户端训练来进行验证。然而,隐私保护的重放会产生数值结果,由于两种执行环境不同,这些结果无法与本地客户端执行直接匹配。我们提出了OPFL,一个用于隐私保护联邦学习的乐观验证框架。为保护数据隐私,OPFL在安全多方计算(MPC)内部执行重放。尽管在MPC和本地GPU上计算的梯度并非逐位相同,我们观察到它们的绝对差异是稳定且有界的。因此,OPFL离线校准一个经验边界,并利用该边界区分良性数值偏差与恶意操纵。为降低昂贵的MPC重放成本,OPFL采用乐观验证,仅对采样的训练步骤进行事后审计。在LeNet、BERT和Qwen上的实验表明,该边界可跨数据集、输入长度和GPU泛化,同时针对模型投毒和基于PGD的攻击实现0%的攻击成功率(ASR)。在LeNet工作负载上,当p=0.01时,OPFL比基于完整MPC的联邦学习快约98.6倍,比基于ZK的方法快约625.5倍。

英文摘要

Federated learning enables multiple clients to collaboratively train models without sharing their private data. However, the lack of visibility into local training makes it difficult to verify whether clients follow the prescribed training procedure or submit malicious updates, such as model poisoning. A natural approach is to replay client training for verification. However, privacy-preserving replay produces numerical results that cannot be directly matched with local client execution because the two run in different environments. We present OPFL, an optimistic verification framework for privacy-preserving federated learning. To protect data privacy, OPFL performs replay inside secure multi-party computation (MPC). Although gradients computed on MPC and local GPUs are not bitwise identical, we observe that their absolute differences are stable and bounded. OPFL therefore calibrates an empirical boundary offline and uses it to distinguish benign numerical deviations from malicious manipulation. To reduce the cost of expensive MPC replay, OPFL adopts optimistic verification by post auditing only sampled training steps. Experiments on LeNet, BERT, and Qwen show that the boundary generalizes across datasets, input lengths, and GPUs, while achieving $0$\% ASR against model poisoning and PGD-based attacks. On a LeNet workload, at $p=0.01$, OPFL is approximately $98.6\times$ faster than full MPC-based FL and $625.5\times$ faster than ZK-based approach.

Comments15 pages, 3 figures, 9 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑