arXiv:2409.14805cs.LGcs.CR2024-09中稿 · publication in IEE…被引 7

提出新型隐蔽持久的联邦学习后门攻击,专攻NLP任务

SDBA: A Stealthy and Long-Lasting Durable Backdoor Attack in Federated Learning

  • 通过分层梯度掩码与顶k%梯度掩码实现隐蔽注入
  • 在多个NLP任务中保持高持久性且绕过主流防御机制
  • 适用于LSTM、GPT-2、T5等模型,凸显防御紧迫性

联邦学习在保护数据隐私的同时训练模型具有广阔前景,但其分布式特性使其易受后门攻击,尤其在自然语言处理(NLP)领域相关研究仍有限。本文提出SDBA,一种针对联邦学习中NLP任务的新型后门攻击机制。通过对LSTM和GPT-2模型的系统分析,识别出最易被注入后门的层,并采用分层梯度掩码与顶k%梯度掩码策略,实现攻击的隐蔽性与长期有效性。此外,为验证任务泛化能力,还对T5模型进行了实验。在下个词预测、情感分析和问答任务上的实验表明,SDBA在持久性方面优于现有后门攻击,并能有效规避主流防御机制,在基于Transformer的GPT-2等模型中表现显著。结果凸显了构建鲁棒防御策略在基于NLP的联邦学习系统中的紧迫性。

原文摘要 · Abstract (English)

Federated learning is a promising approach for training machine learning models while preserving data privacy. However, its distributed nature makes it vulnerable to backdoor attacks, particularly in NLP tasks, where related research remains limited. This paper introduces SDBA, a novel backdoor attack mechanism designed for NLP tasks in federated learning environments. Through a systematic analysis across LSTM and GPT-2 models, we identify the most vulnerable layers for backdoor injection and achieve both stealth and long-lasting durability by applying layer-wise gradient masking and top-k% gradient masking. Also, to evaluate the task generalizability of SDBA, we additionally conduct experiments on the T5 model. Experiments on next-token prediction, sentiment analysis, and question answering tasks show that SDBA outperforms existing backdoors in terms of durability and effectively bypasses representative defense mechanisms, demonstrating notable performance in transformer-based models such as GPT-2. These results highlight the urgent need for robust defense strategies in NLP-based federated learning systems.

联邦学习后门攻击NLP安全模型隐私

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。