节点文献

隐私保护鲁棒聚合联邦学习方案

Privacy-preserving robust aggregation federated learning scheme

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王斌陈运张磊陈杰郑兵

【Author】 WANG Bin;CHEN Yun;ZHANG Lei;CHEN Jie;ZHENG Bing;School of Information and Electronic Technology, Jiamusi University;Heilongjiang Province Key Laboratory of Autonomous Intelligence and Information Processing, School of Information and Electronic Technology, Jiamusi University;Jiamusi Key Laboratory of Satellite Navigation Technology and Equipment Engineering Technology, School of Information and Electronic Technology, Jiamusi University;Department of Science and Technology, Jiamusi University;

【通讯作者】 张磊;

【机构】 佳木斯大学信息电子技术学院佳木斯大学信息电子技术学院黑龙江省自主智能与信息处理重点实验室佳木斯大学信息电子技术学院佳木斯市卫星导航技术与装备工程技术重点实验室佳木斯大学科技处

【摘要】 针对联邦学习训练过程中仍可能遭受隐私泄露和中毒攻击威胁的问题,提出了隐私保护鲁棒聚合联邦学习方案(privacy-preserving robust aggregation federated learning scheme,PRAFL)。客户端使用差分隐私和随机投影技术保护上传的梯度,将隐私保护与恶意检测在客户端进行分离式处理;服务器在受隐私保护的降维梯度空间上,基于改进的马氏距离计算客户端聚合权重;设计鲁棒聚合算法在加噪梯度上实现加权聚合。在3种数据集上进行训练,并按照独立同分布和非独立同分布两种方式划分数据集。并与其它相似算法进行比较,实验结果表明,PRAFL在保护数据隐私的同时,可以有效识别恶意模型,实现模型的正确聚合。

【Abstract】 To address the potential threats of privacy leakage and poisoning attacks during the federated learning training process, a privacy-preserving robust aggregation federated learning scheme(PRAFL) was proposed. On the client side, differential privacy and random projection techniques were employed to protect the uploaded gradients, decoupling privacy preservation from malicious detection at the client. On the server side, client aggregation weights were computed based on an improved Mahalanobis distance within the privacy-preserving, reduced-dimensional gradient space. A robust aggregation algorithm was designed to perform weighted aggregation on the noise-injected gradients. Experiments were conducted by training on three datasets, with data partitioned in both independent and identically distributed(IID) and non-IID manners. Compared with other similar algorithms, the experimental results demonstrate that PRAFL can effectively identify malicious models while preserving data privacy, enabling correct model aggregation.

【基金】 黑龙江省高等学校基本科研业务费优秀创新团队建设基金项目(2023-KYYWF-0639);佳木斯大学国家基金培育基金项目(JMSUGPZR2022-014);佳木斯大学博士专项科研基金启动基金项目(JMSUBZ2022-12);佳木斯大学“东极”学术团队基金项目(DJXSTD202413);黑龙江省省属本科高校优秀青年教师基础研究支持计划基金项目(YQJH2024239);黑龙江省自然科学基金联合基金培育基金项目(PL2024F002);黑龙江省教育厅创新团队基金项目(2024-KYYWF-0611)
  • 【文献出处】 计算机工程与设计 ,Computer Engineering and Design , 编辑部邮箱 ,2026年03期
  • 【分类号】TP309;TP181
  • 【下载频次】22
节点文献中: