MANDERA: MALICIOUS NODE DETECTION IN FEDERATED LEARNING VIA RANKING

成果类型:
Article
署名作者:
Zhu, Wanchuang; Zhao, Benjamin Zi Hao; Luo, Simon; Deng, Ke
署名单位:
University of Sydney; Macquarie University; University of New South Wales Sydney; Tsinghua University
刊物名称:
ANNALS OF APPLIED STATISTICS
ISSN/ISSBN:
1932-6157; 1941-7330
DOI:
10.1214/26-AOAS2147
发表日期:
2026-03
页码:
238-259
关键词:
federated learning Byzantine attack malicious detection ranking DIVIDE-AND-CONQUER regression
摘要:
While federated learning is a popular framework for distributed learning in the machine learning community that allows a global model to be trained across decentralized devices without data exchanging, it is vulnerable to Byzantine attacks where some involved devices are manipulated to poison the model training. Defending federated learning from various Byzantine attacks has been an active research topic in machine learning in recent years. This paper proposes a novel defense strategy called MANDERA, which achieves effective defense via precise detection of the manipulated devices based on a statistical analysis of a ranking matrix obtained from the messages reported by decentralized devices. Compared to existing defense strategies, MAN-DERA enjoys a higher defense efficiency against a wide range of Byzantine attacks and a clear theoretical guarantee. The effectiveness and robustness of MANDERA are further confirmed by a collection of real data analyses.
来源URL: