arXiv:2501.03301cs.CRcs.AI2025-01AAAI被引 8

首次从稀疏聚合视角研究联邦推荐中的拜占庭鲁棒性,揭示其安全漏洞。

Rethinking Byzantine Robustness in Federated Recommendation from Sparse Aggregation Perspective

  • 将单个物品的聚合视为最小执行单元,重新定义稀疏聚合下的拜占庭鲁棒性。
  • 提出Spattack攻击家族,在少数恶意客户端下即可破坏收敛与防御机制。
  • 适用于电商等易被恶意账户注入的联邦推荐场景,警示系统安全设计。

为保护推荐系统中的用户隐私,基于联邦学习(FL)的联邦推荐(FR)应运而生,其将个人数据保留在本地客户端并协同更新模型。与通用FL不同,FR采用独特的稀疏聚合机制:每个物品的嵌入仅由部分客户端更新,而非全部客户端参与的密集聚合。近年来,模型安全性日益受到关注,尤其在拜占庭攻击中,恶意客户端可发送任意更新。由于在电商等领域,恶意客户端可通过注册新账号轻易注入,探索FR中的拜占庭鲁棒性尤为关键。然而,现有工作忽视了FR的稀疏聚合特性,导致不适用。本文首次从稀疏聚合视角研究FR中的拜占庭攻击,具有挑战性:如何在稀疏聚合下定义鲁棒性,以及在有限知识/能力下设计攻击。我们重新定义鲁棒性,以单个物品的聚合为最小执行单元,并提出名为Spattack的攻击策略族,根据攻击者知识与能力分类。大量实验表明,Spattack可在少数恶意客户端下有效阻止收敛,甚至突破防御,对FR系统安全构成严重威胁。

原文摘要 · Abstract (English)

To preserve user privacy in recommender systems, federated recommendation (FR) based on federated learning (FL) emerges, keeping the personal data on the local client and updating a model collaboratively. Unlike FL, FR has a unique sparse aggregation mechanism, where the embedding of each item is updated by only partial clients, instead of full clients in a dense aggregation of general FL. Recently, as an essential principle of FL, model security has received increasing attention, especially for Byzantine attacks, where malicious clients can send arbitrary updates. The problem of exploring the Byzantine robustness of FR is particularly critical since in the domains applying FR, e.g., e-commerce, malicious clients can be injected easily by registering new accounts. However, existing Byzantine works neglect the unique sparse aggregation of FR, making them unsuitable for our problem. Thus, we make the first effort to investigate Byzantine attacks on FR from the perspective of sparse aggregation, which is non-trivial: it is not clear how to define Byzantine robustness under sparse aggregations and design Byzantine attacks under limited knowledge/capability. In this paper, we reformulate the Byzantine robustness under sparse aggregation by defining the aggregation for a single item as the smallest execution unit. Then we propose a family of effective attack strategies, named Spattack, which exploit the vulnerability in sparse aggregation and are categorized along the adversary's knowledge and capability. Extensive experimental results demonstrate that Spattack can effectively prevent convergence and even break down defenses under a few malicious clients, raising alarms for securing FR systems.

联邦推荐拜占庭攻击稀疏聚合安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。