論文名稱(外文):PeerSecure Federated Learning: The Design and Implement of the Robust Peer-to-Peer Federated Learning
指導教授(外文):CHENG, BO-CHAO
外文關鍵詞:Peer-to-Peer Federated LearningData Poisoning AttacksByzantine AttacksCosine SimilarityLogistic RegressionNetwork Security
點對點聯邦學習(Peer-to-Peer Federated Learning, P2P FL)是由傳統的聯邦學習(Federated Learning, FL)演變而來,旨在改善 FL 需要將模型更新傳送到中央伺服器進行聚合的缺點。P2P FL實現了完全去中心化,模型聚合在本地端執行,用戶端可以擁有更高的自主性來決定要使用哪些模型更新。然而,P2P FL同時也面對一些安全性挑戰像是資料毒化攻擊、拜占庭攻擊等。如何讓模型在受到這些攻擊的同時能夠維持一定的抵抗能力,並不被其影響模型性能是一個需要面對的問題。我們提出了一種抵抗攻擊的P2P FL系統名為PSFL(PeerSecure FL System),透過比較餘弦相似度並結合邏輯迴歸模型,找出與本地端模型相似的模型梯度進行模型聚合,並測試新的本地端模型性能是否有進步。透過這樣的過濾、聚合、驗證的步驟來提高模型抵抗攻擊的能力,同時提高本地端模型的準確率。
Peer-to-Peer Federated Learning (P2P FL) originated from standard Federated Learning (FL) and tries to address the drawbacks of FL by eliminating the need for model changes to be transferred to a central server for aggregation. P2P FL achieves total decentralization; model aggregation occurs locally, and the user side has greater autonomy in deciding which model updates to adopt. However, P2P FL has various security issues, such as data poisoning attacks, Byzantine attacks, and so on. The problem of how to allow the model to maintain a certain level of resilience while being subjected to these attacks without having the model's performance impaired by them is one that must be addressed. We propose the PSFL(PeerSecure FL System), a P2P FL system that is resistant to attacks. By analyzing cosine similarity and combining with logistic regression models, we identify model gradients that are comparable to the local model, execute model aggregation, and test the new local model to see if its performance has improved. Filtering, aggregation, and verification increase the model's capacity to resist assaults while also improving the correctness of the local model.
