arXiv:2410.17573cs.LGcs.CR2024-10中稿 · IEEE IRI 2025被引 3

用激活值约束防御联邦学习中的新型后门攻击

Securing Federated Learning against Backdoor Threats with Foundation Model Integration

  • 通过约束隐藏层激活值范围来识别异常
  • 在合成数据上训练时优化约束,实现数据无关防御
  • 同时抵御经典与新型后门攻击,适合隐私敏感场景

联邦学习(FL)在保护隐私的前提下实现分布式模型训练。近期将基础模型(FMs)融入FL虽提升了性能,却引入了新型后门攻击机制:攻击者可利用FM漏洞,在合成数据中嵌入后门。这些被污染的合成数据在全局模型聚合过程中将后门传播至全局模型,进而感染所有客户端模型。现有防御方法因攻击机制不同而失效。本文提出一种无需真实数据的新型防御策略:共享攻击模式在于聚合时隐藏特征空间中的异常激活。因此,我们通过约束内部激活值保持合理范围,有效缓解攻击并保留模型功能。激活约束通过合成数据与FL训练联合优化。大量实验表明该方法对新型和经典后门攻击均有效,优于现有防御方案。

原文摘要 · Abstract (English)

Federated Learning (FL) enables decentralized model training while preserving privacy. Recently, the integration of Foundation Models (FMs) into FL has enhanced performance but introduced a novel backdoor attack mechanism. Attackers can exploit FM vulnerabilities to embed backdoors into synthetic data generated by FMs. During global model fusion, these backdoors are transferred to the global model through compromised synthetic data, subsequently infecting all client models. Existing FL backdoor defenses are ineffective against this novel attack due to its fundamentally different mechanism compared to classic ones. In this work, we propose a novel data-free defense strategy that addresses both classic and novel backdoor attacks in FL. The shared attack pattern lies in the abnormal activations within the hidden feature space during model aggregation. Hence, we propose to constrain internal activations to remain within reasonable ranges, effectively mitigating attacks while preserving model functionality. The activation constraints are optimized using synthetic data alongside FL training. Extensive experiments demonstrate its effectiveness against both novel and classic backdoor attacks, outperforming existing defenses.

联邦学习后门攻击基础模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。