跳到正文
arXiv:cs.LG· Motoki Nakamura·· 3 小时前

基于模拟攻击模式的跨孤岛联邦学习动态搭便车者检测

Dynamic Free-Rider Detection in Cross-Silo Federated Learning via Simulated Attack Patterns

AI 导读

针对跨孤岛联邦学习中早期诚实、后期转为搭便车且模仿全局模型的动态搭便车者,研究者提出检测方法 S2-WEF,在服务器端利用已广播的全局模型模拟潜在攻击的 WEF 模式,并结合提交 WEF 间相互比较得到的偏差分数,通过二维聚类与逐分数分类区分正常客户端与搭便车者。该方法无需代理数据集或预训练,在四个数据集、五种攻击类型上实现了稳健的动态搭便车检测。

正文

View PDF HTML (experimental)

Abstract:Federated learning (FL) enables multiple clients to collaboratively train a global model by aggregating local updates without sharing private data. In this work, we focus on cross-silo FL, where each client typically represents an independent organization. However, cross-silo FL can face the challenge of free-riders, clients who submit fake model parameters without performing actual training to obtain the global model without contributing. Chen et al. proposed a free-rider detection method based on the weight evolving frequency (WEF) of model parameters. This detection approach is practical because it requires neither a proxy dataset nor pre-training. Nevertheless, it struggles to detect ``dynamic'' free-riders who behave honestly in early rounds and later switch to free-riding, particularly under global-model-mimicking attacks such as the delta weight attack and our newly proposed adaptive WEF-camouflage attack. In this paper, we propose a novel detection method S2-WEF that simulates the WEF patterns of potential global-model-mimicking attacks on the server side using previously broadcast global models, and identifies clients whose submitted WEF patterns resemble the simulated ones. To handle a variety of free-rider attack strategies, S2-WEF further combines this simulation-based similarity score with a deviation score computed from mutual comparisons among submitted WEFs, and separates benign and free-rider clients by two-dimensional clustering and per-score classification. This method enables dynamic detection of clients that transition into free-riders during training without proxy datasets or pre-training. We conduct extensive experiments across four datasets and five attack types, demonstrating that S2-WEF provides robust dynamic free-rider detection across diverse settings.
Comments: 12 pages, 1 figure, 12 tables
Subjects: Machine Learning (cs.LG); Cryptography and Security (cs.CR)
Cite as: arXiv:2604.04611 [cs.LG]
  (or arXiv:2604.04611v3 [cs.LG] for this version)
  https://doi.org/10.48550/arXiv.2604.04611

arXiv-issued DOI via DataCite

Submission history

From: Motoki Nakamura [view email]
[v1] Mon, 6 Apr 2026 11:54:05 UTC (194 KB)
[v2] Fri, 12 Jun 2026 09:20:47 UTC (194 KB)
[v3] Thu, 8 Oct 2026 08:34:53 UTC (248 KB)

来源:arXiv:cs.LG · arxiv.org