arXiv:2411.16167cs.LG2024-11ICCV被引 3

Scaffold联邦学习的优化机制反被利用,导致良性客户端无意中助纣为虐。

Mind the Cost of Scaffold! Benign Clients May Even Become Accomplices of Backdoor Attack

  • 通过篡改控制变量,让正常客户端误更新梯度方向。
  • 攻击持续超过60轮,效果是现有方法的3倍以上。
  • 适合研究联邦学习安全性的研究人员关注。

通过使用控制变量校准每个客户端的本地梯度,Scaffold 被广泛认为是缓解联邦学习中数据异构性的有效方案。然而,本文揭示其优越性背后隐藏着更高的安全风险。我们提出 BadSFL,首个针对 Scaffold 的后门攻击,将良性客户端转变为共犯以放大攻击效果。核心思路是唯一地篡改控制变量,微妙引导良性客户端的本地梯度更新朝向攻击者污染方向,使其成为无意识的共犯,显著增强后门持久性。此外,BadSFL 采用 GAN 增强的中毒策略,丰富攻击者数据集,在保持良性与带毒样本高准确率的同时维持隐蔽性。大量实验表明,BadSFL 攻击持久性强,持续超过60个全局轮次,即使停止恶意模型注入,仍比现有基线多持续三倍时间。

原文摘要 · Abstract (English)

By using a control variate to calibrate the local gradient of each client, Scaffold has been widely known as a powerful solution to mitigate the impact of data heterogeneity in Federated Learning. Although Scaffold achieves significant performance improvements, we show that this superiority is at the cost of increased security vulnerabilities. Specifically, this paper presents BadSFL, the first backdoor attack targeting Scaffold, which turns benign clients into accomplices to amplify the attack effect. The core idea of BadSFL is to uniquely tamper with the control variate to subtly steer benign clients' local gradient updates towards the attacker's poisoned direction, effectively turning them into unwitting accomplices and significantly enhancing the backdoor persistence. Additionally, BadSFL leverages a GAN-enhanced poisoning strategy to enrich the attacker's dataset, maintaining high accuracy on both benign and backdoored samples while remaining stealthy. Extensive experiments demonstrate that BadSFL achieves superior attack durability, maintaining effectiveness for over 60 global rounds, lasting up to three times longer than existing baselines even after ceasing malicious model injections.

联邦学习后门攻击安全性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。