arXiv:2412.17740cs.LGeess.SP2024-12被引 1

用敏感度曲线系统攻击分布式学习中的鲁棒聚合器,使其失效。

Sensitivity Curve Maximization: Attacking Robust Aggregators in Distributed Learning

  • 基于鲁棒统计的敏感度曲线,设计最优攻击模式
  • 在多组仿真中验证攻击可使多数鲁棒聚合器失效
  • 适合研究分布式学习安全与对抗攻击的学者

在分布式学习中,各参与方协同解决全局学习问题。随着网络规模扩大,个体节点出现恶意或故障的可能性增加,导致学习过程退化甚至崩溃。传统聚合方法在极低污染率下即可能失效,因此需要鲁棒聚合方案。尽管许多鲁棒聚合器能容忍更高污染率,但已被证明易受精心设计的恶意攻击。本文表明,经典鲁棒统计工具——敏感度曲线(SC),可用于系统性推导针对任意鲁棒聚合器的最优攻击策略,在大多数情况下使其失效。我们在多个仿真中验证了该攻击的有效性。

原文摘要 · Abstract (English)

In distributed learning agents aim at collaboratively solving a global learning problem. It becomes more and more likely that individual agents are malicious or faulty with an increasing size of the network. This leads to a degeneration or complete breakdown of the learning process. Classical aggregation schemes are prone to breakdown at small contamination rates, therefore robust aggregation schemes are sought for. While robust aggregation schemes can generally tolerate larger contamination rates, many have been shown to be susceptible to carefully crafted malicious attacks. In this work, we show how the sensitivity curve (SC), a classical tool from robust statistics, can be used to systematically derive optimal attack patterns against arbitrary robust aggregators, in most cases rendering them ineffective. We show the effectiveness of the proposed attack in multiple simulations.

分布式学习安全攻防鲁棒聚合

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。