客户端侧模型修补技术有效抵御联邦学习中的后门攻击
Client-Side Patching against Backdoor Attacks in Federated Learning
- 在客户端使用对抗学习与模型修补技术
- 非独立同分布场景下后门准确率显著降低
- 适用于数据异构的现实联邦学习场景
联邦学习在去中心化环境中训练模型,但对客户端的信任使其易受恶意参与者发起的后门攻击。尽管已有多种防御方法,但在客户端数据分布异构时效果不佳。本文提出一种新型客户端侧防御机制,利用对抗学习与模型修补技术中和后门攻击影响。在MNIST和Fashion-MNIST数据集上的大量实验表明,该方法在独立同分布与非独立同分布场景下均能有效降低后门准确率,优于LFighter、FLAME和RoseAgg等现有先进防御方法,同时保持对干净数据的高精度。
原文摘要 · Abstract (English)
Federated learning is a versatile framework for training models in decentralized environments. However, the trust placed in clients makes federated learning vulnerable to backdoor attacks launched by malicious participants. While many defenses have been proposed, they often fail short when facing heterogeneous data distributions among participating clients. In this paper, we propose a novel defense mechanism for federated learning systems designed to mitigate backdoor attacks on the clients-side. Our approach leverages adversarial learning techniques and model patching to neutralize the impact of backdoor attacks. Through extensive experiments on the MNIST and Fashion-MNIST datasets, we demonstrate that our defense effectively reduces backdoor accuracy, outperforming existing state-of-the-art defenses, such as LFighter, FLAME, and RoseAgg, in i.i.d. and non-i.i.d. scenarios, while maintaining competitive or superior accuracy on clean data.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。