arXiv:cs.LG· Motoki Nakamura·· 3 小时前
基于模拟攻击模式的跨孤岛联邦学习动态搭便车者检测
Dynamic Free-Rider Detection in Cross-Silo Federated Learning via Simulated Attack Patterns
AI 导读
针对跨孤岛联邦学习中早期诚实、后期转为搭便车且模仿全局模型的动态搭便车者,研究者提出检测方法 S2-WEF,在服务器端利用已广播的全局模型模拟潜在攻击的 WEF 模式,并结合提交 WEF 间相互比较得到的偏差分数,通过二维聚类与逐分数分类区分正常客户端与搭便车者。该方法无需代理数据集或预训练,在四个数据集、五种攻击类型上实现了稳健的动态搭便车检测。
正文
Abstract:Federated learning (FL) enables multiple clients to collaboratively train a global model by aggregating local updates without sharing private data. In this work, we focus on cross-silo FL, where each client typically represents an independent organization. However, cross-silo FL can face the challenge of free-riders, clients who submit fake model parameters without performing actual training to obtain the global model without contributing. Chen et al. proposed a free-rider detection method based on the weight evolving frequency (WEF) of model parameters. This detection approach is practical because it requires neither a proxy dataset nor pre-training. Nevertheless, it struggles to detect ``dynamic'' free-riders who behave honestly in early rounds and later switch to free-riding, particularly under global-model-mimicking attacks such as the delta weight attack and our newly proposed adaptive WEF-camouflage attack. In this paper, we propose a novel detection method S2-WEF that simulates the WEF patterns of potential global-model-mimicking attacks on the server side using previously broadcast global models, and identifies clients whose submitted WEF patterns resemble the simulated ones. To handle a variety of free-rider attack strategies, S2-WEF further combines this simulation-based similarity score with a deviation score computed from mutual comparisons among submitted WEFs, and separates benign and free-rider clients by two-dimensional clustering and per-score classification. This method enables dynamic detection of clients that transition into free-riders during training without proxy datasets or pre-training. We conduct extensive experiments across four datasets and five attack types, demonstrating that S2-WEF provides robust dynamic free-rider detection across diverse settings.
| Comments: | 12 pages, 1 figure, 12 tables |
| Subjects: | Machine Learning (cs.LG); Cryptography and Security (cs.CR) |
| Cite as: | arXiv:2604.04611 [cs.LG] |
| (or arXiv:2604.04611v3 [cs.LG] for this version) | |
| https://doi.org/10.48550/arXiv.2604.04611 arXiv-issued DOI via DataCite |
Submission history
From: Motoki Nakamura [view email]
[v1]
Mon, 6 Apr 2026 11:54:05 UTC (194 KB)
[v2]
Fri, 12 Jun 2026 09:20:47 UTC (194 KB)
[v3]
Thu, 8 Oct 2026 08:34:53 UTC (248 KB)
来源:arXiv:cs.LG · arxiv.org