剖析联邦学习抗拜占庭攻击漏洞,提出新型伪造身份攻击方法
Byzantine-Robust Federated Learning: An Overview With Focus on Developing Sybil-based Attacks to Backdoor Augmented Secure Aggregation Protocols
- 针对鲁棒联邦学习协议的漏洞,设计基于Sybil攻击的新型恶意策略
- 实证揭示现有防护机制在特定攻击下失效,模型准确率显著下降
- 适合安全研究者与联邦学习系统开发者参考,提升防御设计能力
联邦学习(FL)允许多个客户端在保护数据隐私的前提下协作训练机器学习模型。然而,由于其多方参与特性,传统联邦学习方案易受拜占庭攻击影响,攻击者通过注入恶意后门破坏模型性能。已有大量防御方法被提出以应对此类威胁。本文系统梳理并更新了现有防御方法与框架的分类体系,重点分析了鲁棒联邦学习(RoFL)协议的优劣。在此基础上,提出两种新型基于Sybil的攻击,利用RoFL协议中的漏洞实施破坏。最后,提出未来测试建议,详述攻击实现方式,并为改进RoFL协议及整体拜占庭鲁棒框架提供方向。
原文摘要 · Abstract (English)
Federated Learning (FL) paradigms enable large numbers of clients to collaboratively train Machine Learning models on private data. However, due to their multi-party nature, traditional FL schemes are left vulnerable to Byzantine attacks that attempt to hurt model performance by injecting malicious backdoors. A wide variety of prevention methods have been proposed to protect frameworks from such attacks. This paper provides a exhaustive and updated taxonomy of existing methods and frameworks, before zooming in and conducting an in-depth analysis of the strengths and weaknesses of the Robustness of Federated Learning (RoFL) protocol. From there, we propose two novel Sybil-based attacks that take advantage of vulnerabilities in RoFL. Finally, we conclude with comprehensive proposals for future testing, describe and detail implementation of the proposed attacks, and offer direction for improvements in the RoFL protocol as well as Byzantine-robust frameworks as a whole.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。