Federated Hybrid Training and Self-Adversarial Distillation: Towards Robust Edge Networks

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Qiao, Yu, Adhikary, Apurba, Kim, Kitae, Huh, Eui-Nam, Han, Zhu, Hong, Choong Seon
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866915080991408128
author Qiao, Yu
Adhikary, Apurba
Kim, Kitae
Huh, Eui-Nam
Han, Zhu
Hong, Choong Seon
author_facet Qiao, Yu
Adhikary, Apurba
Kim, Kitae
Huh, Eui-Nam
Han, Zhu
Hong, Choong Seon
contents Federated learning (FL) is a distributed training technology that enhances data privacy in mobile edge networks by allowing data owners to collaborate without transmitting raw data to the edge server. However, data heterogeneity and adversarial attacks pose challenges to develop an unbiased and robust global model for edge deployment. To address this, we propose Federated hyBrid Adversarial training and self-adversarial disTillation (FedBAT), a new framework designed to improve both robustness and generalization of the global model. FedBAT seamlessly integrates hybrid adversarial training and self-adversarial distillation into the conventional FL framework from data augmentation and feature distillation perspectives. From a data augmentation perspective, we propose hybrid adversarial training to defend against adversarial attacks by balancing accuracy and robustness through a weighted combination of standard and adversarial training. From a feature distillation perspective, we introduce a novel augmentation-invariant adversarial distillation method that aligns local adversarial features of augmented images with their corresponding unbiased global clean features. This alignment can effectively mitigate bias from data heterogeneity while enhancing both the robustness and generalization of the global model. Extensive experimental results across multiple datasets demonstrate that FedBAT yields comparable or superior performance gains in improving robustness while maintaining accuracy compared to several baselines.
format Preprint
id arxiv_https___arxiv_org_abs_2412_19354
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Federated Hybrid Training and Self-Adversarial Distillation: Towards Robust Edge Networks
Qiao, Yu
Adhikary, Apurba
Kim, Kitae
Huh, Eui-Nam
Han, Zhu
Hong, Choong Seon
Computer Vision and Pattern Recognition
Machine Learning
Federated learning (FL) is a distributed training technology that enhances data privacy in mobile edge networks by allowing data owners to collaborate without transmitting raw data to the edge server. However, data heterogeneity and adversarial attacks pose challenges to develop an unbiased and robust global model for edge deployment. To address this, we propose Federated hyBrid Adversarial training and self-adversarial disTillation (FedBAT), a new framework designed to improve both robustness and generalization of the global model. FedBAT seamlessly integrates hybrid adversarial training and self-adversarial distillation into the conventional FL framework from data augmentation and feature distillation perspectives. From a data augmentation perspective, we propose hybrid adversarial training to defend against adversarial attacks by balancing accuracy and robustness through a weighted combination of standard and adversarial training. From a feature distillation perspective, we introduce a novel augmentation-invariant adversarial distillation method that aligns local adversarial features of augmented images with their corresponding unbiased global clean features. This alignment can effectively mitigate bias from data heterogeneity while enhancing both the robustness and generalization of the global model. Extensive experimental results across multiple datasets demonstrate that FedBAT yields comparable or superior performance gains in improving robustness while maintaining accuracy compared to several baselines.
title Federated Hybrid Training and Self-Adversarial Distillation: Towards Robust Edge Networks
topic Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2412.19354