一种抗拜占庭攻击的联邦学习鲁棒聚合算法OA
A Robust Aggregation Algorithm Defending Against Byzantine Attacks in Federated Learning
针对联邦学习中现有的防御方案在模型过滤时会过度剔除良性模型的问题,提出了一种抗拜占庭攻击的联邦学习鲁棒聚合算法 FLDBA.通过 HDBSCAN 密度聚类算法对模型进行聚类,识别出良性模型集合,并求取良性模型集合中方向最具代表性的模型作为可信模型.以可信模型为基准,利用余弦相似度对聚类结果中可能被误判为异常的良性模型进行筛选,实现对误判的修正.同时设立信誉机制,对模型历史行为进行动态评估,以降低漏判对系统的影响.对于信誉较高的模型,对模型幅值进行自适应缩放,并根据其更新质量赋予不同的聚合权重,提升模型的聚合效果.实验结果表明,在抵御符号翻转攻击时,FLDBA 的准确率比 FLRAM、FLAME、RFLPA、FLTrust和 Krum 提升了 0.18~5.13 百分点,攻击成功率降低了 40.52~61.39 百分点,具有更好的鲁棒性.
To address the issue that existing defense schemes in federated learning tend to over-prune benign mod-els during filtering,a robust aggregation algorithm defending against Byzantine attacks in federated learning(FLD-BA)was proposed.HDBSCAN density-based clustering was employed to group models,to identify the benign clus-ter,and the most representative model in terms of direction was selected as the trusted reference model.Using the trusted model as a benchmark,cosine similarity was utilized to screen potentially misclassified benign models within clusters,thereby to correct misjudgments.Additionally,a reputation mechanism was established to dynamically e-valuate models' historical behaviors,to mitigate the impact of missed detections.For models with high reputation,adaptive magnitude scaling was applied,and differential aggregation weights were assigned based on update quality to further enhance aggregation performance.Experimental results demonstrated that when defending against sign-flipping attacks,FLDBA achieved an accuracy improvement of 0.18 percentage points to 5.13 percentage points compared to FLRAM,FLAME,RFLPA,FLTrust,and Krum,while reducing the attack success rate by 40.52 per-centage points to 61.39 percentage points,exhibiting superior robustness.
张淑芬;李涛;张镇博;钟琪;景忠瑞
华北理工大学 理学院,河北 唐山 063210||河北省数据科学与应用重点实验室(华北理工大学),河北 唐山 063210||唐山市数据科学重点实验室(华北理工大学),河北 唐山 063210华北理工大学 理学院,河北 唐山 063210||河北省数据科学与应用重点实验室(华北理工大学),河北 唐山 063210||唐山市数据科学重点实验室(华北理工大学),河北 唐山 063210华北理工大学 理学院,河北 唐山 063210||河北省数据科学与应用重点实验室(华北理工大学),河北 唐山 063210||唐山市数据科学重点实验室(华北理工大学),河北 唐山 063210华北理工大学 理学院,河北 唐山 063210||河北省数据科学与应用重点实验室(华北理工大学),河北 唐山 063210||唐山市数据科学重点实验室(华北理工大学),河北 唐山 063210华北理工大学 理学院,河北 唐山 063210||河北省数据科学与应用重点实验室(华北理工大学),河北 唐山 063210||唐山市数据科学重点实验室(华北理工大学),河北 唐山 063210
信息技术与安全科学
联邦学习拜占庭攻击鲁棒性信誉加权聚合
federated learningByzantine attacksrobustreputationweighted aggregation
《郑州大学学报(工学版)》 2026 (4)
125-133,9
国家自然科学基金联合基金资助项目(U20A20179)
评论