节点文献
隐私保护鲁棒聚合联邦学习方案
Privacy-preserving robust aggregation federated learning scheme
【摘要】 针对联邦学习训练过程中仍可能遭受隐私泄露和中毒攻击威胁的问题,提出了隐私保护鲁棒聚合联邦学习方案(privacy-preserving robust aggregation federated learning scheme,PRAFL)。客户端使用差分隐私和随机投影技术保护上传的梯度,将隐私保护与恶意检测在客户端进行分离式处理;服务器在受隐私保护的降维梯度空间上,基于改进的马氏距离计算客户端聚合权重;设计鲁棒聚合算法在加噪梯度上实现加权聚合。在3种数据集上进行训练,并按照独立同分布和非独立同分布两种方式划分数据集。并与其它相似算法进行比较,实验结果表明,PRAFL在保护数据隐私的同时,可以有效识别恶意模型,实现模型的正确聚合。
【Abstract】 To address the potential threats of privacy leakage and poisoning attacks during the federated learning training process, a privacy-preserving robust aggregation federated learning scheme(PRAFL) was proposed. On the client side, differential privacy and random projection techniques were employed to protect the uploaded gradients, decoupling privacy preservation from malicious detection at the client. On the server side, client aggregation weights were computed based on an improved Mahalanobis distance within the privacy-preserving, reduced-dimensional gradient space. A robust aggregation algorithm was designed to perform weighted aggregation on the noise-injected gradients. Experiments were conducted by training on three datasets, with data partitioned in both independent and identically distributed(IID) and non-IID manners. Compared with other similar algorithms, the experimental results demonstrate that PRAFL can effectively identify malicious models while preserving data privacy, enabling correct model aggregation.
【Key words】 federated learning; mahalanobis distance; differential privacy; random projection; poisoning attack; robust aggregation; privacy preservation;
- 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2026年03期
- 【分类号】TP309;TP181
- 【下载频次】22