高级检索

    面向数据异质性的联邦学习投毒防御框架

    A Unified Poisoning Defense Framework for Federated Learning under Data Heterogeneity

    • 摘要: 联邦学习能够在不共享原始数据的条件下实现多主体协同建模,为动态异构网络中海量异质终端的协同智能提供了有效支撑,但开放参与机制使其易遭受投毒攻击。恶意客户端可通过标签翻转、后门注入及模型更新操纵等方式破坏全局模型性能。现有联邦学习投毒防御方法多采用鲁棒聚合策略,通过识别并抑制异常更新降低恶意客户端对全局模型的影响。在数据异质性场景下,现有方法存在适应性不足、单一异常指标易误判以及硬剔除策略损失有效信息等问题。针对上述问题,提出一种面向数据异质性的联邦学习投毒防御框架。框架以多维一致性评分的防御方法ConTrust为基础,通过更新方向一致性、更新幅值偏离和主子空间残差实现恶意更新识别;针对非独立同分布场景,设计融合局部近邻参考与跨轮信誉信息的历史行为建模防御方法HistTrust,缓解数据异质性导致的异常误判,提高恶意客户端识别能力。实验覆盖MNIST、FMNIST和CIFAR-10数据集及多种投毒攻击场景,结果表明,所提防御框架在不同数据分布条件下均能有效降低攻击成功率,同时保持较高模型准确率,综合防御性能优于多种典型防御方法。研究表明,针对不同数据分布特点设计差异化防御方法,能够有效提升联邦学习抵御投毒攻击的能力。

       

      Abstract: Federated learning (FL) enables collaborative model training without sharing raw data, making it well suited for collaborative intelligence among massive heterogeneous terminals in dynamic heterogeneous networks. However, its open participation mechanism makes FL vulnerable to poisoning attacks, where malicious clients can degrade the global model by performing label-flipping, backdoor injection, or model update manipulation. Existing poisoning defense methods primarily rely on robust aggregation strategies to mitigate malicious updates. Nevertheless, under data heterogeneity, these methods often suffer from limited adaptability, inaccurate anomaly detection caused by single-metric evaluation, and the loss of useful information due to hard filtering strategies. To address these issues, a unified poisoning defense framework for federated learning under data heterogeneity is proposed. The framework adopts ConTrust, a multidimensional consistency scoring-based defense method, as the foundation, which identifies malicious updates by jointly evaluating update direction consistency, update magnitude deviation, and principal subspace residuals. For non-independent and identically distributed (Non-IID) scenarios, HistTrust, a history behavior modeling-based defense method, is developed by incorporating local neighborhood references and cross-round reputation information, thereby mitigating the misclassification caused by data heterogeneity and improving malicious client identification. Experiments are conducted on the MNIST, Fashion-MNIST, and CIFAR-10 datasets under multiple poisoning attack settings. Experimental results demonstrate that the proposed defense framework consistently reduces the attack success rate while maintaining high model accuracy under different data distributions, outperforming several representative defense methods in overall performance. The study indicates that designing differentiated defense mechanisms for different data distributions can effectively enhance the robustness of FL against poisoning attacks.

       

    /

    返回文章
    返回