Federated Learning (FL) is a promising privacy-preserving machine learning paradigm that allows data owners to collaboratively train models while keeping their data localized. Despite its potential, FL faces challenges related to the trustworthiness of both clients and servers, especially in the presence of curious or malicious adversaries. In this paper, we introduce a novel framework named \underline{\textbf{F}}ederated \underline{\textbf{L}}earning with \underline{\textbf{U}}pdate \underline{\textbf{D}}igest (FLUD), which addresses the critical issues of privacy preservation and resistance to Byzantine attacks within distributed learning environments. FLUD utilizes an innovative approach, the $\mathsf{LinfSample}$ method, allowing clients to compute the $l_{\infty}$ norm across sliding windows of updates as an update digest. This digest enables the server to calculate a shared distance matrix, significantly reducing the overhead associated with Secure Multi-Party Computation (SMPC) by three orders of magnitude while effectively distinguishing between benign and malicious updates. Additionally, FLUD integrates a privacy-preserving, voting-based defense mechanism that employs optimized SMPC protocols to minimize communication rounds. Our comprehensive experiments demonstrate FLUD's effectiveness in countering Byzantine adversaries while incurring low communication and runtime overhead. FLUD offers a scalable framework for secure and reliable FL in distributed environments, facilitating its application in scenarios requiring robust data management and security.
翻译:联邦学习(FL)是一种前景广阔的隐私保护机器学习范式,它允许数据所有者在保持数据本地化的同时协作训练模型。尽管潜力巨大,联邦学习仍面临着客户端与服务器可信度方面的挑战,尤其是在存在好奇或恶意攻击者的情况下。本文提出了一种名为**联邦学习更新摘要**(FLUD)的新颖框架,旨在解决分布式学习环境中隐私保护与抵御拜占庭攻击的关键问题。FLUD采用一种创新方法——$\mathsf{LinfSample}$方法,允许客户端在更新的滑动窗口上计算$l_{\infty}$范数作为更新摘要。该摘要使得服务器能够计算共享距离矩阵,将安全多方计算(SMPC)的相关开销显著降低三个数量级,同时有效区分良性更新与恶意更新。此外,FLUD集成了一个隐私保护的、基于投票的防御机制,该机制采用优化的SMPC协议以最小化通信轮数。我们全面的实验证明,FLUD在对抗拜占庭攻击者方面具有显著效果,同时仅产生较低的通信与运行时开销。FLUD为分布式环境中的安全可靠联邦学习提供了一个可扩展的框架,有助于其在需要强健数据管理与安全性的场景中的应用。