RAB$^2$-DEF:面向 Federate Learning 中弱客户端的动态可解释防御机制
密码学与安全
2025-04-18 v2 人工智能
机器学习
摘要
随着人工智能的普及,监管需求也日益增长,包括数据隐私。在此背景下,联邦学习被提出作为解决数据隐私问题的方案,其分布式学习特性适用于不同来源的数据场景。文中现有防御机制仅关注对抗攻击的防御,忽略了解释性、对弱客户端的公平性、攻击配置的动态性以及对不同攻击类型的鲁棒性等重要特性。本文提出RAB-DEF(Resilient Against Byzantine and backdoor attacks which is Dynamic, Explainable and Fair to poor clients),其利用局部线性解释实现对抗 Byzantine 和 backdoor 攻击的防御,同时具备动态、可解释和对弱客户端公平的特点。我们在图像数据集上测试了RAB-DEF的性能,考虑到当前最先进的防御方法,其结果表明RAB-DEF在可信人工智能方面提升了防御性能及其他关键特性。
引用
@article{arxiv.2410.08244,
title = {RAB$^2$-DEF: Dynamic and explainable defense against adversarial attacks in Federated Learning to fair poor clients},
author = {Nuria Rodríguez-Barroso and M. Victoria Luzón and Francisco Herrera},
journal= {arXiv preprint arXiv:2410.08244},
year = {2025}
}