FedRACE: A Hierarchical and Statistical Framework for Robust Federated Learning
Gang Yan, Sikai Yang, Wan Du
摘要
Integrating large pre-trained models into federated learning (FL) can significantly improve generalization and convergence efficiency. A widely adopted strategy freezes the pre-trained backbone and fine-tunes a lightweight task head, thereby reducing computational and communication costs. However, this partial fine-tuning paradigm introduces new security risks, making the system vulnerable to poisoned updates and backdoor attacks. To address these challenges, we propose FEDRACE, a unified framework for robust FL with partially frozen models. FEDRACE comprises two core components: HStat-Net, a hierarchical network that refines frozen features into compact, linearly separable representations; and DevGuard, a serverside mechanism that detects malicious clients by evaluating statistical deviance in class-level predictions modeling generalized linear models (GLMs). DevGuard further incorporates adaptive thresholding based on theoretical misclassification bounds and employs randomized majority voting to enhance detection reliability. We implement FEDRACE on the FedScale platform and evaluate it on CIFAR-100, Food-101, and Tiny ImageNet under diverse attack scenarios. FEDRACE achieves a true positive rate of up to 99.3% with a false positive rate below 1.2%, while preserving model accuracy and improving generalization.
Existing defenses such as Trimmed-Mean [19], Multi-Krum [20], and reputation-based methods like FLShield [21] and FLAIR [22] often rely on gradient statistics or fixed heuristics. While these methods are effective in some settings, they struggle to detect subtle semantic manipulations, especially when only the head is trainable [23,24]. These limitations raise a key research question: How can we integrate large pre-trained models into FL while enabling reliable and adaptive detection of malicious clients?
To answer this question, we propose FEDRACE, a unified framework for Federated Representationbased Adaptive Client Evaluation. FEDRACE combines hierarchical representation learning with statistical client evaluation to improve FL robustness. It consists of two main components: (1) HStat-Net, a Hierarchical Statistical Network that transforms fixed features into compact and linearly separable representations using a triplet loss, and (2) DevGuard, a server-side evaluation mechanism that uses a generalized linear model (GLM) to identify clients with abnormal semantic behavior through deviance analysis.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper22
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh 等ICML 2021 · 被引用 47,906 次
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu 等S&P 2018 · 被引用 867 次
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma 等NeurIPS 2020 · 被引用 862 次
相关 Paper
- Every Vote Counts: Ranking-Based Training of Federated Learning to Resist Poisoning AttacksHamid Mozaffari, Virat Shejwalkar, Amir HoumansadrUSENIX Security 2023
- RobFL: Robust Federated Learning via Feature Center Separation and Malicious Center DetectionTing Zhou, Ning Liu, Bo Song, Hongtao Lv 等ICDE 2024 · 被引用 3 次
- MESAS: Poisoning Defense for Federated Learning Resilient against Adaptive AttackersTorsten Krauß, Alexandra DmitrienkoCCS 2023 · 被引用 20 次
- 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated LearningHaoyang Li, Qingqing Ye, Haibo Hu, Jin Li 等S&P 2023
- FedRoLA: Robust Federated Learning Against Model Poisoning via Layer-based AggregationGang Yan, Hao Wang, Xu Yuan, Jian LiKDD 2024 · 被引用 6 次
