arXiv:2412.14080cs.LGcs.CR2024-12AAAI被引 2

分布式机器学习同时分散训练与推理,显著提升对抗迁移攻击的鲁棒性。

On the Robustness of Distributed Machine Learning against Transfer Attacks

  • 构建全异构的分布式模型,联合优化训练与推理环节。
  • 在CIFAR10上对主流迁移攻击的鲁棒准确率提升最高达40%。
  • 适合关注模型安全与防御的系统/安全研究者。

尽管分布式机器学习受到广泛关注,但现有研究仅独立考察其在训练或推理阶段的应用。本文首次系统分析同时分布训练与推理过程带来的综合鲁棒性。我们探索了在训练数据、模型结构、调度器、优化器等参数上完全异构的分布式学习范式。基于理论分析和在CIFAR10与FashionMNIST上的大量实验验证,结果表明:此类合理设计的分布式模型在面对当前最先进的迁移攻击时,整体实现了精度-鲁棒性权衡的全面优化,这是现有集成学习或联邦学习无法实现的。例如,在CIFAR10上,针对最强的通用弱点攻击(Common Weakness attack),本方法使鲁棒准确率最高提升40%,且对干净任务准确率影响极小。

原文摘要 · Abstract (English)

Although distributed machine learning (distributed ML) is gaining considerable attention in the community, prior works have independently looked at instances of distributed ML in either the training or the inference phase. No prior work has examined the combined robustness stemming from distributing both the learning and the inference process. In this work, we explore, for the first time, the robustness of distributed ML models that are fully heterogeneous in training data, architecture, scheduler, optimizer, and other model parameters. Supported by theory and extensive experimental validation using CIFAR10 and FashionMNIST, we show that such properly distributed ML instantiations achieve across-the-board improvements in accuracy-robustness tradeoffs against state-of-the-art transfer-based attacks that could otherwise not be realized by current ensemble or federated learning instantiations. For instance, our experiments on CIFAR10 show that for the Common Weakness attack, one of the most powerful state-of-the-art transfer-based attacks, our method improves robust accuracy by up to 40%, with a minimal impact on clean task accuracy.

分布式学习对抗攻击鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。