arXiv:2411.03926cs.CV2024-11被引 1

提出新型分布式多目标后门攻击,有效提升多个后门成功率。

Act in Collusion: Distributed Multi-Target Backdoor Attacks in Federated Learning

  • 设计回放机制降低恶意梯度差异,缓解聚合冲突。
  • 采用复合触发策略,使各后门攻击成功率均超80%。
  • 适合研究联邦学习安全的学者与系统防御开发者。

联邦学习(FL)广泛应用于物联网(IoT)系统,但其分布式训练过程也易受后门攻击。现有研究主要关注单目标或集中式多目标场景,而协同的分布式多目标攻击仍缺乏探索。在实际物联网场景中,一个恶意实体可能控制多个分布式恶意客户端,并为每个客户端分配不同的触发器和目标标签。在此设定下,现有分布式后门方法因恶意更新在聚合时产生冲突,难以同时保持所有后门的有效性。为此,我们提出一种分布式多目标后门攻击(DMBA)。DMBA引入后门回放(BR)机制以减少恶意梯度差异,并采用通道-频率复合触发(CFCT)策略提升触发器可区分性,减轻本地干扰。在多个数据集上的实验表明,DMBA确保所有植入后门的攻击成功率均高于80%,而部分基线方法的攻击成功率低于50%,甚至接近0。

原文摘要 · Abstract (English)

Federated learning (FL) is widely used in Internet-of-Things (IoT) systems, but its distributed training process also exposes it to backdoor attacks. Existing studies mainly consider single-target or centralized multi-target settings, while coordinated distributed multi-target attacks remain underexplored. In practical IoT scenarios, one adversarial entity may control multiple distributed malicious clients and assign each client distinct triggers and target labels. Under this setting, existing distributed backdoor methods often fail to preserve the effectiveness of all backdoors because malicious updates conflict during aggregation. To address this issue, we propose a Distributed Multi-Target Backdoor Attack (DMBA) for FL. DMBA introduces a Backdoor Replay (BR) mechanism to reduce discrepancies among malicious gradients and a Channel-Frequency Composite Trigger (CFCT) strategy to improve trigger distinguishability and alleviate local interference. Experiments on multiple datasets show that DMBA ensures attack success rates above 80% for all implanted backdoors, whereas some baseline backdoors fall below 50% and may even approach 0.

联邦学习后门攻击分布式安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。