Journal of University of Chinese Academy of Sciences ›› 2026, Vol. 43 ›› Issue (4): 553-565.DOI: 10.7523/j.ucas.2024.051
• Electronics and Computer Science • Previous Articles Next Articles
Chenchen XU1(
), Xutong WANG2,3, Taochun WANG1, Fulong CHEN1, Qixu LIU2,3
Received:2023-10-08
Revised:2025-05-17
Online:2026-07-15
Contact:
Chenchen XU
CLC Number:
Chenchen XU, Xutong WANG, Taochun WANG, Fulong CHEN, Qixu LIU. FLShadow:Byzantine-robust federated aggregation based on a trusted shadow model[J]. Journal of University of Chinese Academy of Sciences, 2026, 43(4): 553-565.
Add to citation manager EndNote|Ris|BibTeX
| 参数 | 解释 | 不同数据集、模型结构参数 | ||
|---|---|---|---|---|
| CNN | ResNet20 | |||
| MNIST | Fashion-MNIST | CIFAR-10 | ||
| n | 客户端数量 | 100 | 100 | 100 |
| 每轮选取的客户端数量 | n | n | n | |
| 本地客户端迭代 | 1 | 1 | 1 | |
| 全局模型迭代 | 2 000 | 2 500 | 1 500 | |
| b | 批大小 | 32 | 32 | 64 |
| 联合学习率 | 0.000 3 | 0.006 | 0.018 | |
| f | 恶意客户端占比 | f | f | f |
| 影子数据集规模 | s | s | s | |
| 10 | 10 | 10 | ||
| 0.72 | 0.72 | 0.72 | ||
Table 1 Basic experimental parameter settings
| 参数 | 解释 | 不同数据集、模型结构参数 | ||
|---|---|---|---|---|
| CNN | ResNet20 | |||
| MNIST | Fashion-MNIST | CIFAR-10 | ||
| n | 客户端数量 | 100 | 100 | 100 |
| 每轮选取的客户端数量 | n | n | n | |
| 本地客户端迭代 | 1 | 1 | 1 | |
| 全局模型迭代 | 2 000 | 2 500 | 1 500 | |
| b | 批大小 | 32 | 32 | 64 |
| 联合学习率 | 0.000 3 | 0.006 | 0.018 | |
| f | 恶意客户端占比 | f | f | f |
| 影子数据集规模 | s | s | s | |
| 10 | 10 | 10 | ||
| 0.72 | 0.72 | 0.72 | ||
| 攻击类型 | 聚合规则 | FLShadow | FedAvg | FLTrust | Krum | Median | Trim |
|---|---|---|---|---|---|---|---|
| 无攻击 | no attack | 0.958 5 | 0.962 7 | 0.962 2 | 0.904 8 | 0.946 1 | 0.962 7 |
| 数据投毒 | label flipping | 0.957 3 | 0.964 3 | 0.961 1 | 0.905 9 | 0.945 2 | 0.964 3 |
| 模型投毒 | trim | 0.960 8 | 0.579 3 | 0.956 6 | 0.889 5 | 0.894 4 | 0.577 9 |
| krum | 0.950 4 | 0.947 5 | 0.958 1 | 0.098 0 | 0.930 1 | 0.947 7 | |
| Gaussian | 0.960 4 | 0.958 2 | 0.963 0 | 0.902 8 | 0.940 3 | 0.958 2 | |
| mean | 0.949 1 | 0.936 4 | 0.948 4 | 0.898 7 | 0.921 0 | 0.936 3 | |
| scaling | 0.949 4 | 0.984 3 | 0.962 0 | 0.964 8 | 0.950 6 | 0.986 6 | |
| 均值 | 0.955 1 | 0.904 7 | 0.958 8 | 0.794 9 | 0.932 5 | 0.904 8 | |
Table 2 Comparison of model test accuracy on MNIST dataset
| 攻击类型 | 聚合规则 | FLShadow | FedAvg | FLTrust | Krum | Median | Trim |
|---|---|---|---|---|---|---|---|
| 无攻击 | no attack | 0.958 5 | 0.962 7 | 0.962 2 | 0.904 8 | 0.946 1 | 0.962 7 |
| 数据投毒 | label flipping | 0.957 3 | 0.964 3 | 0.961 1 | 0.905 9 | 0.945 2 | 0.964 3 |
| 模型投毒 | trim | 0.960 8 | 0.579 3 | 0.956 6 | 0.889 5 | 0.894 4 | 0.577 9 |
| krum | 0.950 4 | 0.947 5 | 0.958 1 | 0.098 0 | 0.930 1 | 0.947 7 | |
| Gaussian | 0.960 4 | 0.958 2 | 0.963 0 | 0.902 8 | 0.940 3 | 0.958 2 | |
| mean | 0.949 1 | 0.936 4 | 0.948 4 | 0.898 7 | 0.921 0 | 0.936 3 | |
| scaling | 0.949 4 | 0.984 3 | 0.962 0 | 0.964 8 | 0.950 6 | 0.986 6 | |
| 均值 | 0.955 1 | 0.904 7 | 0.958 8 | 0.794 9 | 0.932 5 | 0.904 8 | |
| 攻击类型 | 聚合规则 | FLShadow | FedAvg | FLTrust | Krum | Median | Trim |
|---|---|---|---|---|---|---|---|
| 无攻击 | no attack | 0.889 8 | 0.903 8 | 0.893 1 | 0.842 3 | 0.851 8 | 0.902 6 |
| 数据投毒 | label flipping | 0.884 4 | 0.900 8 | 0.897 0 | 0.846 8 | 0.866 7 | 0.901 1 |
| 模型投毒 | trim | 0.886 6 | 0.362 0 | 0.877 1 | 0.823 8 | 0.818 6 | 0.353 4 |
| krum | 0.866 5 | 0.882 0 | 0.887 9 | 0.101 9 | 0.833 8 | 0.882 7 | |
| Gaussian | 0.883 7 | 0.899 6 | 0.889 8 | 0.841 0 | 0.860 4 | 0.901 0 | |
| mean | 0.868 0 | 0.879 6 | 0.879 1 | 0.829 8 | 0.840 7 | 0.879 9 | |
| scaling | 0.895 5 | 0.100 0 | 0.898 4 | 0.879 7 | 0.868 4 | 0.100 0 | |
| 均值 | 0.882 0 | 0.704 0 | 0.888 9 | 0.737 9 | 0.848 6 | 0.703 0 | |
Table 3 Comparison of model test accuracy on Fashion-MNIST dataset
| 攻击类型 | 聚合规则 | FLShadow | FedAvg | FLTrust | Krum | Median | Trim |
|---|---|---|---|---|---|---|---|
| 无攻击 | no attack | 0.889 8 | 0.903 8 | 0.893 1 | 0.842 3 | 0.851 8 | 0.902 6 |
| 数据投毒 | label flipping | 0.884 4 | 0.900 8 | 0.897 0 | 0.846 8 | 0.866 7 | 0.901 1 |
| 模型投毒 | trim | 0.886 6 | 0.362 0 | 0.877 1 | 0.823 8 | 0.818 6 | 0.353 4 |
| krum | 0.866 5 | 0.882 0 | 0.887 9 | 0.101 9 | 0.833 8 | 0.882 7 | |
| Gaussian | 0.883 7 | 0.899 6 | 0.889 8 | 0.841 0 | 0.860 4 | 0.901 0 | |
| mean | 0.868 0 | 0.879 6 | 0.879 1 | 0.829 8 | 0.840 7 | 0.879 9 | |
| scaling | 0.895 5 | 0.100 0 | 0.898 4 | 0.879 7 | 0.868 4 | 0.100 0 | |
| 均值 | 0.882 0 | 0.704 0 | 0.888 9 | 0.737 9 | 0.848 6 | 0.703 0 | |
| 攻击类型 | 聚合规则 | FLShadow | FedAvg | FLTrust | Krum | Median | Trim |
|---|---|---|---|---|---|---|---|
| 无攻击 | no attack | 0.729 5 | 0.725 4 | 0.696 6 | 0.377 2 | 0.698 8 | 0.737 6 |
| 数据投毒 | label flipping | 0.749 0 | 0.743 2 | 0.648 5 | 0.466 0 | 0.714 8 | 0.753 6 |
| 模型投毒 | trim | 0.649 0 | 0.193 8 | 0.653 3 | 0.339 3 | 0.319 3 | 0.186 0 |
| krum | 0.682 3 | 0.717 0 | 0.655 5 | 0.119 9 | 0.716 4 | 0.745 8 | |
| Gaussian | 0.731 0 | 0.739 2 | 0.744 3 | 0.375 9 | 0.681 5 | 0.742 7 | |
| mean | 0.716 6 | 0.441 1 | 0.673 4 | 0.417 8 | 0.600 3 | 0.473 1 | |
| scaling | 0.730 4 | 0.101 8 | 0.649 7 | 0.436 4 | 0.708 7 | 0.177 9 | |
| 均值 | 0.712 5 | 0.523 1 | 0.674 5 | 0.361 8 | 0.634 3 | 0.515 2 | |
Table 4 Comparison of model test accuracy on CIFAR-10 dataset
| 攻击类型 | 聚合规则 | FLShadow | FedAvg | FLTrust | Krum | Median | Trim |
|---|---|---|---|---|---|---|---|
| 无攻击 | no attack | 0.729 5 | 0.725 4 | 0.696 6 | 0.377 2 | 0.698 8 | 0.737 6 |
| 数据投毒 | label flipping | 0.749 0 | 0.743 2 | 0.648 5 | 0.466 0 | 0.714 8 | 0.753 6 |
| 模型投毒 | trim | 0.649 0 | 0.193 8 | 0.653 3 | 0.339 3 | 0.319 3 | 0.186 0 |
| krum | 0.682 3 | 0.717 0 | 0.655 5 | 0.119 9 | 0.716 4 | 0.745 8 | |
| Gaussian | 0.731 0 | 0.739 2 | 0.744 3 | 0.375 9 | 0.681 5 | 0.742 7 | |
| mean | 0.716 6 | 0.441 1 | 0.673 4 | 0.417 8 | 0.600 3 | 0.473 1 | |
| scaling | 0.730 4 | 0.101 8 | 0.649 7 | 0.436 4 | 0.708 7 | 0.177 9 | |
| 均值 | 0.712 5 | 0.523 1 | 0.674 5 | 0.361 8 | 0.634 3 | 0.515 2 | |
| [1] | Qasim R, Bangyal W H, Alqarni M A, et al. A fine-tuned BERT-based transfer learning approach for text classification[J]. Journal of Healthcare Engineering, 2022, 2022:3498123. DOI:10.1155/2022/3498123 . |
| [2] | Li Y L. Research and application of deep learning in image recognition[C]//2022 IEEE 2nd International Conference on Power,Electronics and Computer Applications (ICPECA). January 21-23, 2022, Shenyang, China. IEEE, 2022:994-999. DOI:10.1109/ICPECA53709.2022.9718847 . |
| [3] | 赵敏钧,赵亚伟,赵雅捷,等.一种新的基于深度学习的重叠关系联合抽取模型[J].中国科学院大学学报,2022,39(2):240-251.DOI:10.7523/j.ucas.2020.0026 . |
| [4] | 张萌,潘志刚.基于分层模糊聚类和小波卷积神经网络的SAR图像变化检测算法[J]. 中国科学院大学学报,2023,40(5):637-646.DOI:10.7523/j.ucas.2022.013 . |
| [5] | 霍鑫怡,李焱磊,陈龙永,等.基于卷积注意力和胶囊网络的SAR少样本目标识别方法[J].中国科学院大学学报,2022,39(6):783-792.DOI:10.7523/j.ucas.2021.0022 . |
| [6] | 朱嘉桐,卿来云,黄庆明.基于双流LSTM与自监督学习的在线动作检测算法[J]. 中国科学院大学学报, 2022,39(6):827-835.DOI:10.7523/j.ucas.2021.0049 . |
| [7] | 顾育豪,白跃彬.联邦学习模型安全与隐私研究进展[J].软件学报,2023,34(6):2833-2864.DOI:10.13328/j.cnki.jos.006658 . |
| [8] | McMahan H B, Moore E, Ramage D, et al. Communication-efficient learning of deep networks from decentralized data[EB/OL]. arXiv 2023:1602.05629. (2023-01-26) [2023-12-10]. . |
| [9] | Che C J, Li X L, Chen C, et al. A decentralized federated learning framework via committee mechanism with convergence guarantee[J]. IEEE Transactions on Parallel and Distributed Systems, 2022, 33(12): 4783-4800. DOI: 10.1109/TPDS.2022.3202887 . |
| [10] | Karras A, Karras C, Giotopoulos K C, et al. Peer to peer federated learning: towards decentralized machine learning on edge devices [C]//2022 7th South-East Europe Design Automation,Computer Engineering, Computer Networks and Social Media Conference (SEEDA-CECNSM). September 23-25, 2022, Ioannina, Greece. IEEE, 2022: 1-9.DOI: 10.1109/SEEDA-CECNSM57760.2022.9932980 . |
| [11] | Nasr M, Shokri R, Houmansadr A. Comprehensive privacy analysis of deep learning: passive and active white-box inference attacks against centralized and federated learning[C]//2019 IEEE Symposium on Security and Privacy (SP). May 19-23, 2019, San Francisco, CA, USA. IEEE, 2019:739-753. DOI:10.1109/SP.2019.00065 . |
| [12] | Garov K, Dimitrov D I, Jovanović N, et al. Hiding in plain sight: disguising data stealing attacks in federated learning[EB/OL]. arXiv 2023:2306.03013.(2023-06-25)[2023-08-25]. . |
| [13] | Bhagoji A N, Chakraborty S, Mittal P, et al. Analyzing federated learning through an adversarial lens[EB/OL]. arXiv 2019: 1811.12470. (2019-11-25)[2023-12-10]. . |
| [14] | Chen J Y, Huang G H, Zheng H B, et al. Graph-fraudster: Adversarial attacks on graph neural network-based vertical federated learning[J]. IEEE Transactions on Computational Social Systems, 2023, 10(2): 492-506. DOI: 10.1109/TCSS.2022.3161016 . |
| [15] | Tolpegin V, Truex S, Gursoy M E, et al. Data poisoning attacks against federated learning systems[C]//25th European Symposium on Research in Computer Security (ESORICS). September 14-18, 2020, Guildford, UK. Springer, 2020: 480-501. DOI: 10.1007/978-3-030-58951-6_24 . |
| [16] | Fang M H, Cao X Y, Jia J Y, et al. Local model poisoning attacks to byzantine-robust federated learning. [EB/OL]. arXiv 2021:1911.11815. (2021-11-21)[2023-12-10].. |
| [17] | Xiao X, Tang Z, Li C Y, et al. SCA:Sybil-based collusion attacks of IIoT data poisoning in federated learning[J]. IEEE Transactions on Industrial Informatics, 2023, 19(3): 2608-2618. DOI:10.1109/TII.2022.3172310 . |
| [18] | Hidano S, Murakami T, Kawamoto Y. TransMIA: membership inference attacks using transfer shadow training[C]//2021 International Joint Conference on Neural Networks (IJCNN). July 18-22, 2021, Shenzhen, China. IEEE, 2021:1-10. DOI:10.1109/IJCNN52387.2021.9534207 . |
| [19] | Tan J X, Zhong N, Qian Z X, et al. Deep neural network watermarking against model extraction attack[C]//Proceedings of the 31st ACM International Conference on Multimedia (ACM MM). October 29, 2023, Ottawa, Canada. ACM, 2023: 1588-1597. DOI: 10.1145/3581783.3612515 . |
| [20] | Blanchard P, Mhamdi E M E, Guerraoui R, et al. Machine learning with adversaries: Byzantine tolerant gradient descent[C]// Advances in Neural Information Processing Systems (NeurIPS). December 4-9, 2017, Long Beach, USA. MIT Press, 2017:118–128. DOI:10.5555/3294771.3294783 . |
| [21] | Yin D, Chen Y D, Ramchandran K, et al. Byzantine-robust distributed learning: towards optimal statistical rates[EB/OL]. arXiv 2021: 1803.01498. (2021-2-25) [2023-12-10]. . |
| [22] | Cao X Y, Fang M H, Liu J, et al. FLTrust: Byzantine-robust federated learning via trust bootstrapping[C]//28th Annual Network and Distributed System Security Symposium (NDSS). February 21-25, 2021, virtually. ISOC, 2021.DOI:10.14722/ndss.2021.24434 . |
| [23] | 高莹,陈晓峰,张一余,等.联邦学习系统攻击与防御技术研究综述[J].计算机学报,2023,46(9):1781-1805. DOI:10.11897/SP.J.1016.2023.01781 . |
| [24] | Li Y Z, Li Y M, Wu B Y, et al. Invisible backdoor attack with sample-specific triggers[C]//2021 IEEE/CVF International Conference on Computer Vision (ICCV). October 10-17, 2021, Montreal, QC, Canada. IEEE, 2021: 16443-16452. DOI:10.1109/ICCV48922.2021.01615 . |
| [25] | Zhou X C, Xu M, Wu Y M, et al. Deep model poisoning attack on federated learning[J]. Future Internet, 2021, 13(3): 73. DOI: 10.3390/fi13030073 . |
| [26] | Bagdasaryan E, Veit A, Hua Y Q, et al. How to backdoor federated learning[EB/OL]. arXiv 2019:1807.00459.(2019-08-06) [2023-12-10]. . |
| [27] | Cao X Y, Gong N Z. MPAF: model poisoning attacks to federated learning based on fake clients[C]//2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). June 19-20, 2022, New Orleans, LA, USA. IEEE, 2022: 3395-3403. DOI: 10.1109/CVPRW56347.2022.00383 . |
| [28] | Qayyum A, Janjua M U, Qadir J. Making federated learning robust to adversarial attacks by learning data and model association[J]. Computers Security, 2022, 121: 102827. DOI: 10.1016/j.cose.2022.102827 . |
| [29] | Cao X Y, Zhang Z X, Jia J Y, et al. FLCert: provably secure federated learning against poisoning attacks[J]. IEEE Transactions on Information Forensics and Security, 2022, 17: 3691-3705. DOI: 10.1109/TIFS.2022.3212174 . |
| [30] | Guo S W, Zhang T W, Yu H, et al. Byzantine-resilient decentralized stochastic gradient descent[J]. IEEE Transactions on Circuits and Systems for Video Technology, 2022, 32(6): 4096-4106. DOI: 10.1109/TCSVT.2021.3116976 . |
| [31] | Pillutla K, Kakade S M, Harchaoui Z. Robust aggregation for federated learning[J]. IEEE Transactions on Signal Processing, 2022, 70: 1142-1154. DOI: 10.1109/TSP.2022.3153135 . |
| [32] | Kieu T, Yang B, Guo C J, et al. Anomaly detection in time series with robust variational quasi-recurrent autoencoders[C]//2022 IEEE 38th International Conference on Data Engineering (ICDE). May 9-12, 2022, Kuala Lumpur, Malaysia. IEEE, 2022: 1342-1354. DOI: 10.1109/ICDE53745.2022.00105 . |
| [33] | Zhang Z, Zhang Y, Guo D, et al. SecFedNIDS: robust defense for poisoning attack against federated learning-based network intrusion detection system[J]. Future Generation Computer Systems, 2022, 134: 154-169. DOI: 10.1016/j.future.2022.04.010 . |
| [34] | Wang X X, Zhang H Q, Bilal A, et al. WGM-dSAGA: federated learning strategies with Byzantine robustness based on weighted geometric Median[J]. Electronics, 2023, 12(5): 1190. DOI: 10.3390/electronics12051190 . |
| [35] | Li X Y, Qu Z, Zhao S Q, et al. LoMar: a local defense against poisoning attack on federated learning[J]. IEEE Transactions on Dependable and Secure Computing, 2023, 20(1): 437–450. DOI: 10.1109/TDSC.2021.3135422 . |
| [36] | Sharma A, Chen W, Zhao J, et al. TESSERACT: gradient flip score to secure federated learning against model poisoning attacks[EB/OL]. arXiv 2021:2110.10108. (2021-10-19) [2023-12-10]. . |
| [1] | FENG Tao, SUN Guan-Nan, XIA Yan-Hui, MA Jian-Feng. Modeling and detection of ontology-based Byzantine attacks [J]. , 2011, 28(5): 696-705. |
| Viewed | ||||||
|
Full text |
|
|||||
|
Abstract |
|
|||||
Copyright © Journal of University of Chinese Academy of Sciences
Support by Beijing Magtech Co.ltd support@magtech.com.cn