多模型联邦学习提升抗攻击能力,动态调整模型结构防污染。
Multi-Model based Federated Learning Against Model Poisoning Attack: A Deep Learning Based Model Selection for MEC Systems
- 采用主从多模型架构,客户端模型结构动态变化
- 在攻击环境下仍保持与无攻击时相当的准确率
- 适用于动态网络的边缘计算系统,适合安全敏感场景
联邦学习(FL)可在保护数据隐私的前提下实现分布式模型训练,但传统单模型机制易受兼容结构的恶意模型污染攻击。本文提出基于多模型的联邦学习作为主动防御机制,通过一组从属模型训练主模型,并在学习周期内动态改变客户端模型结构,增强抗污染能力。针对移动边缘计算(MEC)系统,将模型选择建模为优化问题,以最小化损失和识别时间,同时满足鲁棒性置信度要求。针对动态网络环境,提出基于深度强化学习的模型选择方法。在拒绝服务(DDoS)攻击检测场景下,实验表明:即使在遭受污染攻击时,系统性能仍可达到无攻击情况下的竞争性准确率,且具备识别时间优化潜力。
原文摘要 · Abstract (English)
Federated Learning (FL) enables training of a global model from distributed data, while preserving data privacy. However, the singular-model based operation of FL is open with uploading poisoned models compatible with the global model structure and can be exploited as a vulnerability to conduct model poisoning attacks. This paper proposes a multi-model based FL as a proactive mechanism to enhance the opportunity of model poisoning attack mitigation. A master model is trained by a set of slave models. To enhance the opportunity of attack mitigation, the structure of client models dynamically change within learning epochs, and the supporter FL protocol is provided. For a MEC system, the model selection problem is modeled as an optimization to minimize loss and recognition time, while meeting a robustness confidence. In adaption with dynamic network condition, a deep reinforcement learning based model selection is proposed. For a DDoS attack detection scenario, results illustrate a competitive accuracy gain under poisoning attack with the scenario that the system is without attack, and also a potential of recognition time improvement.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。