构建联邦学习测试平台,评估其在网络安全中对抗毒化攻击的鲁棒性。
Federated Learning in Adversarial Environments: Testbed Design and Poisoning Resilience in Cybersecurity
- 基于树莓派与Jetson硬件搭建FL测试平台,支持多框架实验。
- 实测表明联邦学习易受毒化攻击,威胁模型与数据完整性。
- 适合关注隐私保护与安全防御的工业界研究者参考。
本文设计并实现了面向网络安全场景的联邦学习(FL)测试平台,评估其在对抗性环境下的抗毒化攻击能力。联邦学习允许多个客户端在不共享原始数据的前提下协同训练全局模型,满足数据隐私与安全需求,尤其适用于网络安全等敏感领域。测试平台基于树莓派和Nvidia Jetson设备,运行Flower框架,支持多种联邦学习框架的对比实验,可评估性能、扩展性及集成便利性。通过入侵检测系统的联邦学习案例研究,验证了该平台在不暴露敏感网络数据的情况下检测异常、保护关键基础设施的能力。针对模型与数据完整性的全面毒化测试表明,尽管联邦学习提升了数据隐私与分布式学习效率,但仍面临毒化攻击的显著威胁,必须通过有效机制加以缓解,以保障其在真实场景中的可靠性。
原文摘要 · Abstract (English)
This paper presents the design and implementation of a Federated Learning (FL) testbed, focusing on its application in cybersecurity and evaluating its resilience against poisoning attacks. Federated Learning allows multiple clients to collaboratively train a global model while keeping their data decentralized, addressing critical needs for data privacy and security, particularly in sensitive fields like cybersecurity. Our testbed, built using Raspberry Pi and Nvidia Jetson hardware by running the Flower framework, facilitates experimentation with various FL frameworks, assessing their performance, scalability, and ease of integration. Through a case study on federated intrusion detection systems, the testbed's capabilities are shown in detecting anomalies and securing critical infrastructure without exposing sensitive network data. Comprehensive poisoning tests, targeting both model and data integrity, evaluate the system's robustness under adversarial conditions. The results show that while federated learning enhances data privacy and distributed learning, it remains vulnerable to poisoning attacks, which must be mitigated to ensure its reliability in real-world applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。