arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.40312cs.LG

压缩足迹作为联邦学习中模型投毒防御的安全信号

Compression Footprints as Security Signals for Model-Poisoning Defense in Federated Learning

Sachi Shome, William Eiers

首次发表
浏览论文内容

中文总结 AI 辅助

本研究提出将有损压缩的响应作为安全信号,通过压缩足迹区分诚实与恶意更新,并开发CRAFT鲁棒聚合方法,在无需额外通信下有效防御模型投毒攻击。

中文摘要 AI 辅助

有损压缩在联邦学习(FL)中被广泛使用,但通常被视为错误来源,而传统的投毒防御则检查更新的几何形状。在这项工作中,我们反而将压缩器的响应视为一种安全信号:有损压缩引起的输入相关失真和负载行为可以揭示诚实更新与攻击生成更新之间的差异。我们引入了“压缩足迹”的概念:由有损压缩器引起的重建、方向、稀疏性和负载统计的低维集合。我们刻画了压缩足迹区分诚实更新与恶意更新的充分条件,并将我们的发现应用于CRAFT(基于足迹信任的压缩引导鲁棒聚合)服务器端鲁棒聚合方法。至关重要的是,在严格诚实多数假设下,CRAFT使用服务器可验证的足迹,不需要客户端元数据,也不需要知道恶意客户端的数量,并且除了压缩的FL管道外不增加任何通信开销。此外,虽然CRAFT假设严格诚实多数,但它不需要事先知道恶意客户端的数量。我们观察到,误差有界有损压缩器(EBLC)足迹比Top-K足迹提供更强的区分度,并且足迹信任抑制了恶意影响。我们在IID客户端数据下,针对六种标准模型投毒攻击、三个数据集和六种鲁棒聚合基线,以36%的恶意参与率评估了CRAFT,发现CRAFT在18个设置中的7个中始终达到最佳准确率,在其他设置中与最佳准确率相差在1.7个百分点以内。我们的结果表明,有损压缩既可以作为通信机制,也可以作为FL中鲁棒聚合的安全信号。

英文摘要

Lossy compression is widely used in Federated Learning (FL) but is generally treated as an error source, while conventional poisoning defenses inspect update geometry. In this work, we instead treat the compressor's response as a security signal: the input-dependent distortion and payload behavior induced by lossy compression can expose differences between honest and attack-generated updates. We introduce the concept of a \emph{compression footprint}: the low-dimensional collection of reconstruction, directional, sparsity, and payload statistics induced by a lossy compressor. We characterize sufficient conditions under which compression footprints separate honest and malicious updates, and operationalize our findings in the CRAFT (\emph{Compression-guided Robust Aggregation via Footprint Trust}) server-side robust aggregation method. Crucially, under a strict honest-majority assumption, CRAFT uses server-verifiable footprints, requires no client-side metadata nor knowledge of the number of malicious clients, and adds no communication beyond the compressed FL pipeline. Moreover, while CRAFT assumes a strict honest majority, it does not require the number of malicious clients to be known in advance. We observe that error-bounded lossy compressor (EBLC) footprints provide stronger separation than Top-K footprints and that footprint trust suppresses malicious influence. We evaluate CRAFT under IID client data with 36\% malicious participation across six standard model-poisoning attacks, three datasets, and six robust aggregation baselines, finding that CRAFT consistently achieves the best accuracy in 7 out of 18 settings and within 1.7 percentage points of the best in the others. Our results show that lossy compression can serve as both a communication mechanism and a security signal for robust aggregation in FL.

发表机构

  • Stevens Institute of Technology(史蒂文斯理工学院)

机构由 AI 辅助整理,请以论文原文为准。

↑