BEV-SGD: Best Effort Voting SGD against Byzantine Attacks for Analog Aggregation based Federated Learning Over the Air

BEV-SGD: Best Effort Voting SGD against Byzantine Attacks for Analog Aggregation based Federated Learning Over the Air
复制标题

BEV-SGD:针对基于模拟聚合的空中联邦学习的拜占庭攻击的尽力投票 SGD

DOI:
10.1109/jiot.2022.3164339
复制
发表时间:
2022
影响因子:
10.6
通讯作者:
Zhi Tian
Zhi Tian
中科院分区:
计算机科学1区
文献类型:
--
作者:
Xin Fan;Yue Wang;Yan Huo;Zhi Tian

文献摘要

被引文献

相似文献

作为一种有前景的分布式学习技术,基于模拟聚合的空中联邦学习(FLOA)在边缘计算范式下提供了高通信效率和隐私配置。当所有边缘设备(worker)通过共同共享的时频资源同时将其本地更新上传到参数服务器(PS)时,PS仅获得平均更新而不是单独的本地更新。虽然这种并发传输和聚合方案减少了延迟和通信成本,但不幸的是,它使 FLOA 容易受到拜占庭攻击。本文针对拜占庭弹性FLOA,从分析FLOA中广泛用于功率控制的通道反转(CI)机制开始。我们的理论分析表明,尽管 CI 在良性场景下可以取得良好的学习性能,但在防御拜占庭攻击的能力有限的情况下,它无法很好地工作。然后,我们提出了一种称为尽力而为投票(BEV)功率控制策略的新颖方案,该方案与随机梯度下降(SGD)相结合。我们的 BEV-SGD 允许所有工作人员以最大传输功率发送本地更新,从而增强了 FLOA 对拜占庭攻击的鲁棒性。在最坏情况攻击下,我们分别得出 FLOA 与 CI 和 BEV 功率控制策略的预期收敛率。速率比较表明,我们的 BEV-SGD 在更好的收敛行为方面优于 CI,这已通过实验模拟得到验证。
As a promising distributed learning technology, analog aggregation-based federated learning over the air (FLOA) provides high communication efficiency and privacy provisioning under the edge computing paradigm. When all edge devices (workers) simultaneously upload their local updates to the parameter server (PS) through commonly shared time-frequency resources, the PS obtains the averaged update only rather than the individual local ones. While such a concurrent transmission and aggregation scheme reduces the latency and communication costs, it unfortunately renders FLOA vulnerable to Byzantine attacks. Aiming at Byzantine-resilient FLOA, this article starts from analyzing the channel inversion (CI) mechanism that is widely used for power control in FLOA. Our theoretical analysis indicates that although CI can achieve good learning performance in the benign scenarios, it fails to work well with limited defensive capability against Byzantine attacks. Then, we propose a novel scheme called the best effort voting (BEV) power control policy that is integrated with stochastic gradient descent (SGD). Our BEV-SGD enhances the robustness of FLOA to Byzantine attacks, by allowing all the workers to send their local updates at their maximum transmit power. Under worst-case attacks, we derive the expected convergence rates of FLOA with CI and BEV power control policies, respectively. The rate comparison reveals that our BEV-SGD outperforms its counterpart with CI in terms of better convergence behavior, which is verified by experimental simulations.