对比8种联邦学习模型在标签翻转攻击下的鲁棒性差异。
An Empirical Analysis of Federated Learning Models Subject to Label-Flipping Adversarial Attack
- 通过模拟10~100个客户端的标签翻转攻击,测试模型表现。
- 发现不同模型对攻击者比例和翻转率的敏感度差异显著。
- 结果有助于设计更抗攻击的联邦学习系统,适合安全研究者参考。
本文实证分析了多种联邦学习模型在标签翻转攻击下的表现。研究涵盖多元逻辑回归(MLR)、支持向量分类器(SVC)、多层感知机(MLP)、卷积神经网络(CNN)、循环神经网络(RNN)、随机森林、XGBoost及长短期记忆网络(LSTM)。针对每种模型,我们在10个与100个联邦客户端的场景下进行实验,将恶意客户端比例从10%增至100%,同时每个恶意客户端的标签翻转率也从10%到100%变化。结果表明,不同模型在对抗攻击中的鲁棒性存在显著差异,其敏感度受恶意客户端占比和单个客户端标签翻转率两个因素共同影响。研究讨论了这些发现对实际应用的潜在意义。
原文摘要 · Abstract (English)
In this paper, we empirically analyze adversarial attacks on selected federated learning models. The specific learning models considered are Multinominal Logistic Regression (MLR), Support Vector Classifier (SVC), Multilayer Perceptron (MLP), Convolution Neural Network (CNN), %Recurrent Neural Network (RNN), Random Forest, XGBoost, and Long Short-Term Memory (LSTM). For each model, we simulate label-flipping attacks, experimenting extensively with 10 federated clients and 100 federated clients. We vary the percentage of adversarial clients from 10% to 100% and, simultaneously, the percentage of labels flipped by each adversarial client is also varied from 10% to 100%. Among other results, we find that models differ in their inherent robustness to the two vectors in our label-flipping attack, i.e., the percentage of adversarial clients, and the percentage of labels flipped by each adversarial client. We discuss the potential practical implications of our results.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。