arXiv:2410.02042cs.LGcs.AI2024-10IJCAI被引 7

攻击者通过恶意更新放大联邦学习中的算法偏见,同时保持模型可用性。

EAB-FL: Exacerbating Algorithmic Bias through Model Poisoning Attacks in Federated Learning

  • 设计新型投毒攻击EAB-FL,针对性增强模型对特定群体的不公平性
  • 在三个数据集上验证攻击有效,即使有公平优化和安全聚合仍可成功
  • 揭示隐私保护框架下的新风险,适合关注模型公平性的研究者阅读

联邦学习(FL)允许多方在不共享私有数据的前提下协同训练共享模型,因其独特的隐私优势而日益流行。然而,由于数据异质性和参与方选择的差异,FL模型可能对某些人口群体(如种族、性别)产生偏差。已有研究提出多种评估FL算法群体公平性的策略,但这些策略在面对恶意攻击时的有效性尚未充分探索。尽管现有研究已揭示了多种针对FL系统的威胁(如模型投毒攻击),其主要目标是降低模型准确率,而利用有毒模型更新加剧模型不公平性的潜力仍未被挖掘。本文提出一种新型模型投毒攻击EAB-FL,旨在加剧群体不公平性的同时维持较高的模型性能。在三个数据集上的大量实验表明,该攻击即使在采用最先进的公平性优化算法和安全聚合规则的情况下依然有效且高效。

原文摘要 · Abstract (English)

Federated Learning (FL) is a technique that allows multiple parties to train a shared model collaboratively without disclosing their private data. It has become increasingly popular due to its distinct privacy advantages. However, FL models can suffer from biases against certain demographic groups (e.g., racial and gender groups) due to the heterogeneity of data and party selection. Researchers have proposed various strategies for characterizing the group fairness of FL algorithms to address this issue. However, the effectiveness of these strategies in the face of deliberate adversarial attacks has not been fully explored. Although existing studies have revealed various threats (e.g., model poisoning attacks) against FL systems caused by malicious participants, their primary aim is to decrease model accuracy, while the potential of leveraging poisonous model updates to exacerbate model unfairness remains unexplored. In this paper, we propose a new type of model poisoning attack, EAB-FL, with a focus on exacerbating group unfairness while maintaining a good level of model utility. Extensive experiments on three datasets demonstrate the effectiveness and efficiency of our attack, even with state-of-the-art fairness optimization algorithms and secure aggregation rules employed.

联邦学习投毒攻击算法偏见公平性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。