《计算机应用》唯一官方网站 ›› 2026, Vol. 46 ›› Issue (7): 2196-2207.DOI: 10.11772/j.issn.1001-9081.2025070875
任志强1,2,3, 陈学斌1,2,3(
), 屈昌盛1,2,3
收稿日期:2025-08-04
修回日期:2025-09-11
接受日期:2025-09-11
发布日期:2025-11-05
出版日期:2026-07-10
通讯作者:
陈学斌
作者简介:任志强(2000—),男,四川广元人,硕士研究生,CCF会员,主要研究方向:数据安全、隐私保护基金资助:
Zhiqiang REN1,2,3, Xuebin CHEN1,2,3(
), Changsheng QU1,2,3
Received:2025-08-04
Revised:2025-09-11
Accepted:2025-09-11
Online:2025-11-05
Published:2026-07-10
Contact:
Xuebin CHEN
About author:REN Zhiqiang, born in 2000, M. S. candidate. His research interests include data security, privacy protection.Supported by:摘要:
联邦学习作为一种新兴的分布式机器学习方法,能够在保护数据隐私的前提下,使多个参与方协同训练模型。然而,现有的研究表明,联邦学习系统容易受到拜占庭攻击,此类攻击可能导致模型性能显著下降或阻碍模型收敛。针对此类攻击,提出一种主动防御框架,以检测恶意更新并减轻恶意更新的影响。该框架包括恶意更新检测与恶意更新削弱2个核心模块。其中,恶意更新检测模块主要通过构建恶意样本库,结合评分机制与聚类算法识别恶意更新;而恶意更新削弱模块则通过向客户端分发特定的“测试模型”,根据客户端响应的模型更新,利用评分及权重分配机制调整聚合权重,从而有效降低恶意更新对全局模型的负面影响。实验结果表明,针对部分攻击类型,本文框架的恶意更新检测准确率接近100%,且通过恶意更新削弱在大部分攻击场景下均保证良性更新的聚合权重占比超过90%。
中图分类号:
任志强, 陈学斌, 屈昌盛. 面向联邦学习中拜占庭攻击的主动防御框架[J]. 计算机应用, 2026, 46(7): 2196-2207.
Zhiqiang REN, Xuebin CHEN, Changsheng QU. Active defense framework against Byzantine attacks in federated learning[J]. Journal of Computer Applications, 2026, 46(7): 2196-2207.
| 防御方法 | 相关工作 | 优点 | 缺点 |
|---|---|---|---|
| 鲁棒性聚合 | 文献[ | 特定场景下防御性能高 | 数据异构场景下不能保证模型收敛;计算成本高 |
| 异常检测 | 文献[ | 有效地区分恶意更新与正常更新 | 存在误报、漏报问题 |
| 信誉系统 | 文献[ | 信誉系统建立后,持续生效且能降低计算开销 | 建立信誉系统难度较大;逃避信誉系统检测的攻击者会造成持续危害 |
| 主动防御 | 文献[ | 能更有效地区分恶意更新与良性异常更新 | 有额外的通信开销或计算开销 |
表1 防御方法对比
Tab. 1 Comparison of defense methods
| 防御方法 | 相关工作 | 优点 | 缺点 |
|---|---|---|---|
| 鲁棒性聚合 | 文献[ | 特定场景下防御性能高 | 数据异构场景下不能保证模型收敛;计算成本高 |
| 异常检测 | 文献[ | 有效地区分恶意更新与正常更新 | 存在误报、漏报问题 |
| 信誉系统 | 文献[ | 信誉系统建立后,持续生效且能降低计算开销 | 建立信誉系统难度较大;逃避信誉系统检测的攻击者会造成持续危害 |
| 主动防御 | 文献[ | 能更有效地区分恶意更新与良性异常更新 | 有额外的通信开销或计算开销 |
| 数据集 | 攻击 | IID | Non-IID | ||
|---|---|---|---|---|---|
| D_P | E_J | D_P | E_J | ||
| MNIST | LFA | 100.00 | 0.00 | 90.61 | 1.09 |
| MNA | 100.00 | 0.00 | 100.00 | 0.00 | |
| SFA | 76.56 | 7.06 | 67.56 | 10.87 | |
| ALIE | 100.00 | 0.00 | 100.00 | 0.11 | |
| MinMax | 100.00 | 0.00 | 100.00 | 0.00 | |
| F-MNIST | LFA | 100.00 | 0.00 | 90.75 | 0.89 |
| MNA | 100.00 | 0.00 | 100.00 | 0.00 | |
| SFA | 70.10 | 7.85 | 68.17 | 11.12 | |
| ALIE | 100.00 | 0.00 | 100.00 | 0.07 | |
| MinMax | 100.00 | 0.00 | 100.00 | 0.00 | |
| CIFAR | LFA | 99.95 | 0.00 | 84.03 | 1.21 |
| MNA | 100.00 | 0.00 | 100.00 | 0.00 | |
| SFA | 88.10 | 2.99 | 71.12 | 8.53 | |
| ALIE | 100.00 | 0.00 | 100.00 | 0.01 | |
| MinMax | 100.00 | 0.00 | 100.00 | 0.00 | |
表2 MUD的检测性能 ( %)
Tab. 2 MUD detection performance
| 数据集 | 攻击 | IID | Non-IID | ||
|---|---|---|---|---|---|
| D_P | E_J | D_P | E_J | ||
| MNIST | LFA | 100.00 | 0.00 | 90.61 | 1.09 |
| MNA | 100.00 | 0.00 | 100.00 | 0.00 | |
| SFA | 76.56 | 7.06 | 67.56 | 10.87 | |
| ALIE | 100.00 | 0.00 | 100.00 | 0.11 | |
| MinMax | 100.00 | 0.00 | 100.00 | 0.00 | |
| F-MNIST | LFA | 100.00 | 0.00 | 90.75 | 0.89 |
| MNA | 100.00 | 0.00 | 100.00 | 0.00 | |
| SFA | 70.10 | 7.85 | 68.17 | 11.12 | |
| ALIE | 100.00 | 0.00 | 100.00 | 0.07 | |
| MinMax | 100.00 | 0.00 | 100.00 | 0.00 | |
| CIFAR | LFA | 99.95 | 0.00 | 84.03 | 1.21 |
| MNA | 100.00 | 0.00 | 100.00 | 0.00 | |
| SFA | 88.10 | 2.99 | 71.12 | 8.53 | |
| ALIE | 100.00 | 0.00 | 100.00 | 0.01 | |
| MinMax | 100.00 | 0.00 | 100.00 | 0.00 | |
| 数据集 | 条件 | LFA | MNA | SFA | ALIE | MinMax |
|---|---|---|---|---|---|---|
| MNIST | IID | 98.73 | 99.97 | 100.00 | 66.49 | 96.94 |
| Non-IID | 98.14 | 99.88 | 99.62 | 66.32 | 96.37 | |
| F-MNIST | IID | 99.07 | 99.94 | 100.00 | 66.49 | 98.17 |
| Non-IID | 98.22 | 99.83 | 99.64 | 66.31 | 94.12 | |
| CIFAR | IID | 98.43 | 99.87 | 100.00 | 66.49 | 97.07 |
| Non-IID | 98.26 | 99.78 | 99.92 | 66.49 | 96.65 |
表3 良性更新的平均总权重占比 ( %)
Tab. 3 Average total weight ratios of benign updates
| 数据集 | 条件 | LFA | MNA | SFA | ALIE | MinMax |
|---|---|---|---|---|---|---|
| MNIST | IID | 98.73 | 99.97 | 100.00 | 66.49 | 96.94 |
| Non-IID | 98.14 | 99.88 | 99.62 | 66.32 | 96.37 | |
| F-MNIST | IID | 99.07 | 99.94 | 100.00 | 66.49 | 98.17 |
| Non-IID | 98.22 | 99.83 | 99.64 | 66.31 | 94.12 | |
| CIFAR | IID | 98.43 | 99.87 | 100.00 | 66.49 | 97.07 |
| Non-IID | 98.26 | 99.78 | 99.92 | 66.49 | 96.65 |
| 恶意客户端占比 | IID | Non-IID |
|---|---|---|
| 10 | 86.50 | 85.49 |
| 20 | 86.56 | 85.38 |
| 30 | 86.53 | 85.08 |
| 40 | 86.55 | 83.08 |
表4 在MNIST数据集上不同恶意客户端占比下ALIE攻击对模型准确率的影响 ( %)
Tab. 4 Impact of ALIE attack on model accuracy under different malicious client ratios on MNIST dataset
| 恶意客户端占比 | IID | Non-IID |
|---|---|---|
| 10 | 86.50 | 85.49 |
| 20 | 86.56 | 85.38 |
| 30 | 86.53 | 85.08 |
| 40 | 86.55 | 83.08 |
| 数据集 | 攻击 | FedAvg | Multi-Krum | Median | Trim-Mean | ClippedClustering | Dnc | RECESS | MUW | MUD |
|---|---|---|---|---|---|---|---|---|---|---|
| MNIST | None | 86.89 | 86.64 | 86.67 | 86.65 | 86.64 | 86.76 | 86.62 | 86.69 | 86.67 |
| LFA | 85.47 | 86.65 | 86.26 | 86.43 | 86.81 | 86.78 | 86.45 | 86.90 | 86.79 | |
| MNA | — | 86.70 | 86.31 | 86.16 | 86.73 | 86.71 | — | 86.17 | 86.80 | |
| SFA | — | 86.97 | 85.70 | 85.48 | 85.63 | 86.68 | 86.39 | 86.85 | 85.61 | |
| ALIE | 86.56 | 86.87 | 86.46 | 86.63 | 86.85 | 86.66 | 86.56 | 86.65 | 86.63 | |
| MinMax | 85.78 | 85.51 | 85.54 | 85.74 | 85.37 | 86.61 | 85.86 | 86.51 | 86.70 | |
| F-MNIST | None | 86.66 | 86.64 | 86.83 | 86.66 | 86.68 | 86.67 | 86.66 | 86.57 | 86.84 |
| LFA | 85.59 | 86.74 | 86.55 | 86.34 | 86.67 | 86.63 | 86.55 | 86.60 | 86.84 | |
| MNA | — | 86.90 | 86.48 | 86.31 | 86.64 | 86.71 | — | 85.59 | 86.96 | |
| SFA | — | 86.58 | 85.78 | 85.37 | 85.59 | 86.56 | 86.51 | 86.77 | 85.06 | |
| ALIE | 86.90 | 86.54 | 86.17 | 86.67 | 86.57 | 86.68 | 86.81 | 86.72 | 86.69 | |
| MinMax | 85.89 | 85.56 | 85.79 | 85.88 | 85.37 | 86.44 | 86.07 | 86.47 | 86.76 | |
| CIFAR | None | 67.91 | 66.79 | 66.68 | 66.62 | 66.11 | 66.12 | 67.00 | 67.27 | 67.03 |
| LFA | 60.45 | 65.33 | 63.91 | 62.53 | 66.11 | 66.22 | 41.71 | 65.30 | 66.91 | |
| MNA | — | 65.97 | 65.44 | 65.33 | 66.37 | 66.02 | — | 65.48 | 66.91 | |
| SFA | — | 65.70 | 62.67 | 61.06 | 63.57 | 66.58 | 65.52 | 65.52 | 63.73 | |
| ALIE | 67.14 | 65.60 | 66.42 | 66.77 | 65.70 | 66.07 | 65.22 | 65.95 | 66.13 | |
| MinMax | 64.78 | 64.35 | 64.16 | 64.14 | 62.26 | 66.45 | 44.02 | 63.21 | 66.84 |
表5 IID条件下不同防御方法对模型准确率的影响 ( %)
Tab. 5 Impact of different defense methods on model accuracy under IID conditions
| 数据集 | 攻击 | FedAvg | Multi-Krum | Median | Trim-Mean | ClippedClustering | Dnc | RECESS | MUW | MUD |
|---|---|---|---|---|---|---|---|---|---|---|
| MNIST | None | 86.89 | 86.64 | 86.67 | 86.65 | 86.64 | 86.76 | 86.62 | 86.69 | 86.67 |
| LFA | 85.47 | 86.65 | 86.26 | 86.43 | 86.81 | 86.78 | 86.45 | 86.90 | 86.79 | |
| MNA | — | 86.70 | 86.31 | 86.16 | 86.73 | 86.71 | — | 86.17 | 86.80 | |
| SFA | — | 86.97 | 85.70 | 85.48 | 85.63 | 86.68 | 86.39 | 86.85 | 85.61 | |
| ALIE | 86.56 | 86.87 | 86.46 | 86.63 | 86.85 | 86.66 | 86.56 | 86.65 | 86.63 | |
| MinMax | 85.78 | 85.51 | 85.54 | 85.74 | 85.37 | 86.61 | 85.86 | 86.51 | 86.70 | |
| F-MNIST | None | 86.66 | 86.64 | 86.83 | 86.66 | 86.68 | 86.67 | 86.66 | 86.57 | 86.84 |
| LFA | 85.59 | 86.74 | 86.55 | 86.34 | 86.67 | 86.63 | 86.55 | 86.60 | 86.84 | |
| MNA | — | 86.90 | 86.48 | 86.31 | 86.64 | 86.71 | — | 85.59 | 86.96 | |
| SFA | — | 86.58 | 85.78 | 85.37 | 85.59 | 86.56 | 86.51 | 86.77 | 85.06 | |
| ALIE | 86.90 | 86.54 | 86.17 | 86.67 | 86.57 | 86.68 | 86.81 | 86.72 | 86.69 | |
| MinMax | 85.89 | 85.56 | 85.79 | 85.88 | 85.37 | 86.44 | 86.07 | 86.47 | 86.76 | |
| CIFAR | None | 67.91 | 66.79 | 66.68 | 66.62 | 66.11 | 66.12 | 67.00 | 67.27 | 67.03 |
| LFA | 60.45 | 65.33 | 63.91 | 62.53 | 66.11 | 66.22 | 41.71 | 65.30 | 66.91 | |
| MNA | — | 65.97 | 65.44 | 65.33 | 66.37 | 66.02 | — | 65.48 | 66.91 | |
| SFA | — | 65.70 | 62.67 | 61.06 | 63.57 | 66.58 | 65.52 | 65.52 | 63.73 | |
| ALIE | 67.14 | 65.60 | 66.42 | 66.77 | 65.70 | 66.07 | 65.22 | 65.95 | 66.13 | |
| MinMax | 64.78 | 64.35 | 64.16 | 64.14 | 62.26 | 66.45 | 44.02 | 63.21 | 66.84 |
| 数据集 | 攻击 | FedAvg | Multi-Krum | Median | Trim-Mean | ClippedClustering | Dnc | RECESS | MUW | MUD |
|---|---|---|---|---|---|---|---|---|---|---|
| MNIST | None | 85.37 | 82.95 | 80.16 | 81.70 | 84.22 | 82.10 | 85.50 | 85.33 | 85.41 |
| LFA | 83.06 | 84.67 | 79.58 | 80.60 | 84.18 | 84.41 | 81.04 | 84.94 | 84.85 | |
| MNA | — | 84.74 | 80.20 | 82.22 | 84.93 | 84.84 | — | 81.00 | 84.81 | |
| SFA | — | 84.59 | 76.55 | 78.80 | 76.12 | 78.24 | 76.24 | 84.63 | 76.77 | |
| ALIE | 85.38 | 84.15 | 83.23 | 83.55 | 84.93 | 83.83 | 80.03 | 84.84 | 85.10 | |
| MinMax | 71.57 | 52.22 | 76.30 | 74.51 | 66.73 | 82.44 | 77.37 | 83.51 | 85.30 | |
| F-MNIST | None | 85.44 | 82.89 | 79.89 | 81.56 | 84.42 | 81.63 | 85.31 | 85.30 | 85.44 |
| LFA | 83.03 | 84.83 | 79.61 | 80.67 | 84.56 | 84.53 | 78.93 | 84.83 | 84.97 | |
| MNA | — | 84.71 | 80.09 | 82.23 | 84.88 | 84.81 | — | 81.23 | 84.98 | |
| SFA | — | 84.55 | 78.20 | 78.39 | 76.22 | 80.02 | 77.02 | 84.71 | 78.03 | |
| ALIE | 85.43 | 84.14 | 83.05 | 83.50 | 84.89 | 83.75 | 79.83 | 85.13 | 84.91 | |
| MinMax | 71.30 | 51.99 | 75.83 | 75.02 | 68.41 | 82.76 | 76.38 | 83.30 | 84.88 | |
| CIFAR | None | 63.55 | 53.86 | 43.88 | 52.56 | 57.88 | 50.69 | 64.03 | 64.03 | 63.72 |
| LFA | 56.77 | 54.06 | 37.03 | 47.12 | 60.96 | 51.79 | 29.97 | 63.63 | 61.74 | |
| MNA | — | 62.31 | 44.95 | 48.78 | 63.54 | 61.37 | — | 60.60 | 62.86 | |
| SFA | — | 62.57 | 34.85 | 47.56 | 52.64 | 57.42 | 25.57 | 63.18 | 48.60 | |
| ALIE | 64.05 | 53.04 | 49.94 | 53.60 | 58.88 | 54.39 | 47.15 | 62.68 | 62.58 | |
| MinMax | 30.33 | — | 30.12 | 30.47 | — | 40.57 | 29.63 | 60.01 | 62.79 |
表6 Non-IID条件下不同防御方法对模型准确率的影响 ( %)
Tab. 6 Impact of different defense methods on model accuracy under Non-IID conditions
| 数据集 | 攻击 | FedAvg | Multi-Krum | Median | Trim-Mean | ClippedClustering | Dnc | RECESS | MUW | MUD |
|---|---|---|---|---|---|---|---|---|---|---|
| MNIST | None | 85.37 | 82.95 | 80.16 | 81.70 | 84.22 | 82.10 | 85.50 | 85.33 | 85.41 |
| LFA | 83.06 | 84.67 | 79.58 | 80.60 | 84.18 | 84.41 | 81.04 | 84.94 | 84.85 | |
| MNA | — | 84.74 | 80.20 | 82.22 | 84.93 | 84.84 | — | 81.00 | 84.81 | |
| SFA | — | 84.59 | 76.55 | 78.80 | 76.12 | 78.24 | 76.24 | 84.63 | 76.77 | |
| ALIE | 85.38 | 84.15 | 83.23 | 83.55 | 84.93 | 83.83 | 80.03 | 84.84 | 85.10 | |
| MinMax | 71.57 | 52.22 | 76.30 | 74.51 | 66.73 | 82.44 | 77.37 | 83.51 | 85.30 | |
| F-MNIST | None | 85.44 | 82.89 | 79.89 | 81.56 | 84.42 | 81.63 | 85.31 | 85.30 | 85.44 |
| LFA | 83.03 | 84.83 | 79.61 | 80.67 | 84.56 | 84.53 | 78.93 | 84.83 | 84.97 | |
| MNA | — | 84.71 | 80.09 | 82.23 | 84.88 | 84.81 | — | 81.23 | 84.98 | |
| SFA | — | 84.55 | 78.20 | 78.39 | 76.22 | 80.02 | 77.02 | 84.71 | 78.03 | |
| ALIE | 85.43 | 84.14 | 83.05 | 83.50 | 84.89 | 83.75 | 79.83 | 85.13 | 84.91 | |
| MinMax | 71.30 | 51.99 | 75.83 | 75.02 | 68.41 | 82.76 | 76.38 | 83.30 | 84.88 | |
| CIFAR | None | 63.55 | 53.86 | 43.88 | 52.56 | 57.88 | 50.69 | 64.03 | 64.03 | 63.72 |
| LFA | 56.77 | 54.06 | 37.03 | 47.12 | 60.96 | 51.79 | 29.97 | 63.63 | 61.74 | |
| MNA | — | 62.31 | 44.95 | 48.78 | 63.54 | 61.37 | — | 60.60 | 62.86 | |
| SFA | — | 62.57 | 34.85 | 47.56 | 52.64 | 57.42 | 25.57 | 63.18 | 48.60 | |
| ALIE | 64.05 | 53.04 | 49.94 | 53.60 | 58.88 | 54.39 | 47.15 | 62.68 | 62.58 | |
| MinMax | 30.33 | — | 30.12 | 30.47 | — | 40.57 | 29.63 | 60.01 | 62.79 |
| [1] | Zhang C, Xie Y, Bai H, et al. A survey on federated learning [J]. Knowledge-Based Systems, 2021, 216: No.106775. |
| [2] | McMahan H B, Moore E, Ramage D, et al. Communication-efficient learning of deep networks from decentralized data [C]// AISTATS 2017. New York: JMLR.org, 2017: 1273-1282. |
| [3] | Kourou K, Exarchos T P, Exarchos K P, et al. Machine learning applications in cancer prognosis and prediction [J]. Computational and Structural Biotechnology Journal, 2015, 13: 8-17. |
| [4] | Ravì D, Wong C, Deligianni F, et al. Deep learning for health informatics [J]. IEEE Journal of Biomedical and Health Informatics, 2017, 21(1): 4-21. |
| [5] | El Sallab A, Abdou M, Perot E, et al. Deep reinforcement learning framework for autonomous driving [C]// Electronic Imaging 2017. Springfield, VA: Society for Imaging Science and Technology, 2017: 70-76. |
| [6] | Babaev D, Savchenko M, Tuzhilin A, et al. E.T.-RNN: applying deep learning to credit loan applications [C]// KDD 2019. New York: ACM, 2019: 2183-2190. |
| [7] | Fiore U, De Santis A, Perla F, et al. Using generative adversarial networks for improving classification effectiveness in credit card fraud detection [J]. Information Sciences, 2019, 479: 448-455. |
| [8] | Tolpegin V, Truex S, Gursoy M E, et al. Data poisoning attacks against federated learning systems [C]// ESORICS 2020. Cham: Springer, 2020: 480-501. |
| [9] | Li S, Ngai E, Voigt T. Byzantine-robust aggregation in federated learning empowered industrial IoT [J]. IEEE Transactions on Industrial Informatics, 2023, 19(2): 1165-1175. |
| [10] | Li L, Xu W, Chen T, et al. RSA: Byzantine-robust stochastic aggregation methods for distributed learning from heterogeneous datasets [C]// AAAI 2019. Palo Alto: AAAI Press, 2019: 1544-1551. |
| [11] | Baruch M, Baruch G, Goldberg Y. A little is enough: circumventing defenses for distributed learning [C]// NeurIPS 2019. Red Hook: Curran Associates Inc., 2019: 8635-8645. |
| [12] | Shejwalkar V, Houmansadr A. Manipulating the Byzantine: optimizing model poisoning attacks and defenses for federated learning [EB/OL]. [2025-08-16]. . |
| [13] | Blanchard P, El Mhamdi E M, Guerraoui R, et al. Machine learning with adversaries: Byzantine tolerant gradient descent [C]// NeurIPS 2017. Red Hook: Curran Associates Inc., 2017: 118-128. |
| [14] | Yin D, Chen Y, Kannan R, et al. Byzantine-robust distributed learning: towards optimal statistical rates [C]// ICML 2018. New York: JMLR.org, 2018: 5650-5659. |
| [15] | Awan S, Luo B, Li F. CONTRA: defending against poisoning attacks in federated learning [C]// ESORICS 2021. Cham: Springer, 2021: 455-475. |
| [16] | Yan H, Zhang W, Chen Q, et al. RECESS vaccine for federated learning: proactive defense against model poisoning attacks [C]// NeurIPS 2023. Red Hook: Curran Associates Inc., 2023: 8702-8713. |
| [17] | Bagdasaryan E, Veit A, Hua Y, et al. How to backdoor federated learning [C]// AISTATS 2020. New York: JMLR.org, 2020: 2938-2948. |
| [18] | Xie C, Huang K, Chen P Y, et al. DBA: distributed backdoor attacks against federated learning [EB/OL]. (2018-04-08) [2024-05-24]. . |
| [19] | Sun Z, Kairouz P, Suresh A T, et al. Can you really backdoor federated learning? [PP/OL]. V2. arXiv (2019-12-02) [2024-05-24]. . |
| [20] | Wang H, Sreenivasan K, Rajput S, et al. Attack of the tails: yes, you really can backdoor federated learning [C]// NeurIPS 2020. Red Hook: Curran Associates Inc., 2020: 16070-16084. |
| [21] | Li S, Ngai E C H, Voigt T. An experimental study of Byzantine-robust aggregation schemes in federated learning [J]. IEEE Transactions on Big Data, 2024, 10(6): 975-988. |
| [22] | Sattler F, Müller K R, Wiegand T, et al. On the Byzantine robustness of clustered federated learning [C]// ICASSP 2020. Piscataway: IEEE, 2020: 8861-8865. |
| [23] | El Mhamdi E M, Guerraoui R, Rouault S. The hidden vulnerability of distributed learning in Byzantium [C]// ICML 2018. New York: JMLR.org, 2018: 3521-3530. |
| [24] | Wang N, Xiao Y, Chen Y, et al. FLARE: defending federated learning against model poisoning attacks via latent space representations [C]// AsiaCCS 2022. New York: ACM, 2022: 946-958. |
| [25] | Rodríguez-Barroso N, Martínez-Cámara E, Luzón M V, et al. Dynamic defense against Byzantine poisoning attacks in federated learning [J]. Future Generation Computer Systems, 2022, 133: 1-9. |
| [26] | Cao X, Fang M, Liu J, et al. FLTrust: Byzantine-robust federated learning via trust bootstrapping [EB/OL]. [2025-08-16]. . |
| [27] | Muñoz-González L, Co K T, Lupu E C. Byzantine-robust federated machine learning through adaptive model averaging [PP/OL]. arXiv (2019-09-12) [2025-08-16]. . |
| [28] | Pillutla K, Kakade S M, Harchaoui Z. Robust aggregation for federated learning [J]. IEEE Transactions on Signal Processing, 2022, 70: 1142-1154. |
| [29] | Ebron S C, Yang K. FedTruth: Byzantine-robust and backdoor-resilient federated learning framework [PP/OL]. arXiv (2023-11-17) [2025-08-16]. . |
| [30] | Cao D, Chang S, Lin Z, et al. Understanding distributed poisoning attack in federated learning [C]// ICPADS 2019. Piscataway: IEEE, 2019: 233-239. |
| [31] | Li D, Wong W E, Wang W, et al. Detection and mitigation of label-flipping attacks in federated learning systems with KPCA and K-means [C]// DSA 2021. Piscataway: IEEE, 2021: 551-559. |
| [32] | Zhang Z, Cao X, Jia J, et al. FLDetector: defending federated learning against model poisoning attacks via detecting malicious clients [C]// KDD 2022. New York: ACM, 2022: 2545-2555. |
| [33] | Li S, Cheng Y, Wang W, et al. Learning to detect malicious clients for robust federated learning [PP/OL]. arXiv (2020-02-01) [2025-08-16]. . |
| [34] | Fang M, Cao X, Jia J, et al. Local model poisoning attacks to Byzantine-robust federated learning [C]// USENIX Security 2020. Berkeley: USENIX Association, 2020: 1623-1640. |
| [35] | Hsu T M H, Qi H, Brown M. Measuring the effects of non-identical data distribution for federated visual classification [PP/OL]. arXiv (2019-09-13) [2024-05-24]. . |
| [1] | 孙天乐, 曹腾飞. 车联网中基于Stackelberg博弈的联邦学习质量感知激励机制[J]. 《计算机应用》唯一官方网站, 2026, 46(7): 2229-2238. |
| [2] | 陈坚伟, 陆佳炜, 王琪冰, 赵梦珂. 基于动态时空编码器的电梯多元时间序列异常检测方法[J]. 《计算机应用》唯一官方网站, 2026, 46(7): 2364-2372. |
| [3] | 钟琪, 张淑芬, 张镇博, 李涛. 基于梯度特征的联邦学习后门防御算法[J]. 《计算机应用》唯一官方网站, 2026, 46(7): 2184-2195. |
| [4] | 董汦楗, 顾瑞春. 融合动态特征对齐与温度感知聚合的联邦学习框架[J]. 《计算机应用》唯一官方网站, 2026, 46(6): 1746-1755. |
| [5] | 谢斌红, 朱二丹, 张睿. 基于外观-运动协同建模的视频异常检测[J]. 《计算机应用》唯一官方网站, 2026, 46(5): 1551-1559. |
| [6] | 俞浩, 范菁, 郗恩康, 金亚东, 董华, 孙伊航. 边缘异构下的高效联邦分割学习框架HEFSL[J]. 《计算机应用》唯一官方网站, 2026, 46(5): 1397-1407. |
| [7] | 姜志, 陈学斌, 罗长银, 甄子业. 联邦学习中改进Kolmogorov-Arnold网络的混合优化框架[J]. 《计算机应用》唯一官方网站, 2026, 46(4): 1023-1033. |
| [8] | 索逸凡, 刘松华, 郝秋智. 基于高阶特征聚合的时间序列异常检测方法[J]. 《计算机应用》唯一官方网站, 2026, 46(4): 1131-1138. |
| [9] | 平欢, 夏战国, 刘思诚, 刘奇翰, 李春磊. 基于多层联邦学习的终端数据隐私保护方案[J]. 《计算机应用》唯一官方网站, 2026, 46(3): 830-838. |
| [10] | 王磊, 周文轩, 贾柠晖, 屈志昊. 面向隐私敏感物联网数据的联邦学习双向通信压缩[J]. 《计算机应用》唯一官方网站, 2026, 46(3): 887-898. |
| [11] | 郗恩康, 范菁, 金亚东, 董华, 俞浩, 孙伊航. 联邦学习在隐私安全领域面临的威胁综述[J]. 《计算机应用》唯一官方网站, 2026, 46(3): 798-808. |
| [12] | 马凯光, 陈学斌, 菅银龙, 王柳, 高远. 基于混合序列模型与联邦类平衡算法的网络入侵检测[J]. 《计算机应用》唯一官方网站, 2026, 46(3): 857-866. |
| [13] | 尹春勇, 张不凡. 基于多尺度的多变量时间序列异常检测模型[J]. 《计算机应用》唯一官方网站, 2026, 46(3): 790-797. |
| [14] | 董莉梅, 李雁姿, 李家印, 许力. 基于邻域增强的无监督图异常检测[J]. 《计算机应用》唯一官方网站, 2026, 46(2): 458-466. |
| [15] | 郭泽一, 李凤莲, 徐利春. 基于双重决策机制的深度符号回归算法[J]. 《计算机应用》唯一官方网站, 2026, 46(2): 406-415. |
| 阅读次数 | ||||||
|
全文 |
|
|||||
|
摘要 |
|
|||||