用博弈论设计自适应防御,对抗多种未知的联邦学习攻击
Meta Stackelberg Game: Robust Federated Learning against Adaptive and Mixed Poisoning Attacks
- 通过强化学习模拟强攻击行为,在预训练中构建防御策略
- 在多种未知攻击下仍保持高鲁棒性,有效抵御模型投毒和后门攻击
- 适合关注安全联邦学习的科研与工程人员
联邦学习易受各类安全威胁。尽管已有多种防御机制,但通常为非自适应且针对特定攻击类型,难以应对多种不确定、未知且动态变化的攻击策略。本文将混合攻击下的对抗联邦学习建模为贝叶斯斯塔克尔伯格马尔可夫博弈,提出基于预训练与在线适应的元-斯塔克尔伯格防御框架。核心思想是在预训练阶段利用强化学习模拟强攻击行为,再设计元强化学习防御以应对多样化和自适应攻击。我们开发了一种高效的元学习方法求解该博弈,实现稳健且自适应的联邦学习防御。理论上,所提元-斯塔克尔伯格学习算法在 $O(cepsilon^{-2})$ 次梯度迭代内收敛至一阶 $cepsilon$-元均衡点,每轮迭代需 $O(cepsilon^{-4})$ 个样本。实验表明,该框架在面对多种不确定、未知类型的强模型投毒和后门攻击时表现卓越。
原文摘要 · Abstract (English)
Federated learning (FL) is susceptible to a range of security threats. Although various defense mechanisms have been proposed, they are typically non-adaptive and tailored to specific types of attacks, leaving them insufficient in the face of multiple uncertain, unknown, and adaptive attacks employing diverse strategies. This work formulates adversarial federated learning under a mixture of various attacks as a Bayesian Stackelberg Markov game, based on which we propose the meta-Stackelberg defense composed of pre-training and online adaptation. {The gist is to simulate strong attack behavior using reinforcement learning (RL-based attacks) in pre-training and then design meta-RL-based defense to combat diverse and adaptive attacks.} We develop an efficient meta-learning approach to solve the game, leading to a robust and adaptive FL defense. Theoretically, our meta-learning algorithm, meta-Stackelberg learning, provably converges to the first-order $\varepsilon$-meta-equilibrium point in $O(\varepsilon^{-2})$ gradient iterations with $O(\varepsilon^{-4})$ samples per iteration. Experiments show that our meta-Stackelberg framework performs superbly against strong model poisoning and backdoor attacks of uncertain and unknown types.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。