提出新型高效攻击框架,破解垂直联邦图学习的防御机制。
Query-Efficient Adversarial Attack Against Vertical Federated Graph Learning
- 通过伪造本地数据并构建影子模型,实现低查询量攻击
- 在5个真实数据集上显著提升攻击成功率,超越已有方法
- 适合研究联邦学习安全与对抗攻击的学者参考
图神经网络(GNN)因其对图结构数据的表征学习能力受到广泛关注。然而,分布式数据孤岛限制了GNN性能。垂直联邦学习(VFL)作为一种新兴技术,使GNN能够处理分布式图数据。尽管垂直联邦图学习(VFGL)发展迅速,其对对抗攻击的鲁棒性尚未被探索。虽然已有大量针对集中式GNN的对抗攻击方法,但在VFGL场景下攻击效果受限。据我们所知,这是首个研究针对VFGL的对抗攻击的工作。本文提出一种查询高效的混合攻击框架NA2(Neuron-based Adversarial Attack),显著提升集中式攻击在VFGL中的表现。具体而言,恶意客户端通过操纵本地训练数据,在隐蔽中提升自身贡献;随后基于篡改数据构建影子模型,模拟服务器模型行为。该影子模型可仅用少量查询即提高多种集中式攻击的成功率。在五个真实世界基准上的大量实验表明,NA2显著提升了对VFGL的攻击性能,即使在防御者已知攻击方法的自适应防御条件下仍达到顶尖水平。此外,通过敏感神经元识别与t-SNE可视化,提供了对NA2有效性的可解释性分析。
原文摘要 · Abstract (English)
Graph neural network (GNN) has captured wide attention due to its capability of graph representation learning for graph-structured data. However, the distributed data silos limit the performance of GNN. Vertical federated learning (VFL), an emerging technique to process distributed data, successfully makes GNN possible to handle the distributed graph-structured data. Despite the prosperous development of vertical federated graph learning (VFGL), the robustness of VFGL against the adversarial attack has not been explored yet. Although numerous adversarial attacks against centralized GNNs are proposed, their attack performance is challenged in the VFGL scenario. To the best of our knowledge, this is the first work to explore the adversarial attack against VFGL. A query-efficient hybrid adversarial attack framework is proposed to significantly improve the centralized adversarial attacks against VFGL, denoted as NA2, short for Neuron-based Adversarial Attack. Specifically, a malicious client manipulates its local training data to improve its contribution in a stealthy fashion. Then a shadow model is established based on the manipulated data to simulate the behavior of the server model in VFGL. As a result, the shadow model can improve the attack success rate of various centralized attacks with a few queries. Extensive experiments on five real-world benchmarks demonstrate that NA2 improves the performance of the centralized adversarial attacks against VFGL, achieving state-of-the-art performance even under potential adaptive defense where the defender knows the attack method. Additionally, we provide interpretable experiments of the effectiveness of NA2 via sensitive neurons identification and visualization of t-SNE.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。