Journal of Computer Applications
Next Articles
Received:
Revised:
Accepted:
Online:
Published:
孙辰1,缪祥华1,2,夏彬杰1,吕艳1,刘晨曦1
通讯作者:
Abstract: Federated Learning (FL) stands as a robust distributed machine learning paradigm that enables collaborative model training across multiple users while preserving the privacy of their local data. However, its inherent distributed architecture renders FL highly susceptible to attacks, where malicious clients may upload corrupted or adversarial updates to compromise the global model’s integrity. To address this challenge, a comprehensive scoring-based aggregation approach called Federated Comprehensive Score (FedCS) was proposed. Firstly, spectral analysis, cosine similarity, Euclidean distance, and historical behavior were leveraged to comprehensively evaluate the client models from four dimensions. Then, adaptive weight assignment was performed according to the training phase, and a weighted comprehensive score was calculated. Finally, an exponential decay function was adopted to softly exclude malicious updates, suppressing the impact of attacks while preserving benign information. Experimental results demonstrate that under different attack ratios and Non-Independent and Identically Distributed (Non-IID) data distributions, FedCS improves the model accuracy (MA) by an absolute improvement of 79 percentage points on the MNIST dataset compared to the attacked model. When data is Independent and Identically Distributed (IID), compared with the Feature-guided Defense against Byzantine and Adaptive attacks (FDBA) method, FedCS increases model accuracy by 7.86 and 2.00 percentage points for Byzantine and partial-knowledge attacks on the FashionMNIST dataset, 4.54 and 0.59 percentage points on the CIFAR10 dataset. Under both Independent and Identically Distributed (IID) and Non-Independent and Identically Distributed (Non-IID) data divisions, and against various attack ratios, the FedCS consistently has advantages over other defense methods, and ensures the utilization of client models.
Key words: Federated Learning (FL), Byzantine attack, model robustness, comprehensive scoring, anomaly detection
摘要: 联邦学习(FL)是一种强大的分布式机器学习范式,在保障用户之间协作训练的基础上,实现了用户隐私数据的保护,但这种分布式特性使得联邦学习容易遭受攻击。因此,本文提出一种基于综合评分的聚合方法——FedCS (Federated Comprehensive Score)。首先,通过谱分析、余弦相似度、欧氏距离和历史行为这4个角度对客户端模型进行综合评估;其次,根据训练阶段进行自适应权重分配,加权计算综合评分;最后,采用指数衰减函数对恶意更新实行软排除,在压制攻击影响的同时保留良性信息。实验结果表明,在不同攻击比例和数据非独立同分布(Non-IID)时,FedCS在MNIST数据集上相较于无防御的被攻击模型,模型准确率(Model Accuracy, MA)绝对提升了79个百分点;在数据独立同分布(IID)时,相较于FDBA (Feature-guided Defense against Byzantine and Adaptive attacks)方法,FedCS在FashionMNIST数据集上对于拜占庭攻击、部分知识攻击的模型准确率分别提升了7.86和2.00个百分点,在CIFAR10数据集上模型准确率分别提升了4.54和0.59个百分点。在IID和Non-IID划分下,面对不同比例的攻击,FedCS相较于其他防御方法均有优势,且保障了客户端模型的利用率。
关键词: 联邦学习, 拜占庭攻击, 模型鲁棒性, 综合评分, 异常检测
CLC Number:
TP399
孙辰 缪祥华 夏彬杰 吕艳 刘晨曦. 联邦学习中基于综合评分的聚合方法[J]. 《计算机应用》唯一官方网站, DOI: 10.11772/j.issn.1001-9081.2026040469.
/ Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: https://www.joca.cn/EN/10.11772/j.issn.1001-9081.2026040469