FedAegis: Edge-Based Byzantine-Robust Federated Learning for Heterogeneous Data

FedAegis: Edge-Based Byzantine-Robust Federated Learning for Heterogeneous Data
复制标题

DOI:
10.1109/globecom48099.2022.10000981
复制
发表时间:
2022-12
期刊:
GLOBECOM 2022 - 2022 IEEE Global Communications Conference
影响因子:
--
通讯作者:
Fangtong Zhou;Ruozhou Yu;Zhouyu Li;Huayue Gu;Xiaojian Wang
Fangtong Zhou;Ruozhou Yu;Zhouyu Li;Huayue Gu;Xiaojian Wang
中科院分区:
其他
文献类型:
--
作者:
Fangtong Zhou;Ruozhou Yu;Zhouyu Li;Huayue Gu;Xiaojian Wang

文献摘要

相似文献

本文研究了如何设计一种基于边缘的联合学习算法称为FedAegis的联合学习算法,在异质数据分布和拜占庭对手下都可以在RO-BUST中。本地数据分布的差异为联邦学习的培训过程带来了次优的结果,而拜占庭对手的旨在防止培训过程在分布式学习系统中融合。在本文中,我们表明,基于边缘的层次联合学习体系结构可以通过利用边缘节点在地理上接近本地设备簇来帮助解决这一难题。通过将分布强大的全球损失函数与局部拜占庭式抗议汇总规则相结合,Fedaegis可以防御无法操纵本地设备连接到边缘节点的远程拜占庭对手,同时考虑了整个良性本地设备的全球数据异质性。使用MNIST,FMNIST和CIFAR-IO数据集进行的实验表明,在异质数据和各种攻击方案下,我们提出的算法可以实现收敛性和高精度和/或最坏情况的准确性。
This paper studies how an edge-based federated learning algorithm called FedAegis can be designed to be ro-bust under both heterogeneous data distributions and Byzantine adversaries. The divergence of local data distributions leads to suboptimal results for the training process of federated learning, and the Byzantine adversaries aim to prevent the training process from converging in a distributed learning system. In this paper, we show that an edge-based hierarchical federated learning architecture can help tackle this dilemma by utilizing edge nodes geographically close to clusters of local devices. By combining a distributionally robust global loss function with a local Byzantine-robust aggregation rule, FedAegis can defend against remote Byzantine adversaries who cannot manipulate local devices' connections to edge nodes, meanwhile accounting for global data heterogeneity across benign local devices. Experiments with the MNIST, FMNIST and CIFAR-IO datasets show that our proposed algorithm can achieve convergence and high accuracy under heterogeneous data and various attack scenarios, while state-of-the-art defenses and robustness mechanisms are non-converging or have reduced average and/or worst-case accuracy.