arXiv:2501.09320cs.LGcs.CR2025-01被引 6

提出新型协作式垂直联邦学习后门攻击,无需服务器梯度信息即可高效触发模型偏移。

Cooperative Decentralized Backdoor Attacks on Vertical Federated Learning

  • 利用本地训练的标签推断模型与对抗者图拓扑共识,协同选择并注入触发器。
  • 攻击成功率显著高于现有方法,在相同主任务性能下提升15%以上。
  • 适用于研究垂直联邦学习安全性的研究人员,尤其关注多敌手协作场景。

联邦学习(FL)易受后门攻击,攻击者通过在数据样本中嵌入触发器,使模型在特定分类标签上行为异常。尽管水平联邦学习中的后门攻击已受广泛关注,但垂直联邦学习(VFL)中的攻击仍不明确——在VFL中,各设备持有样本的不同特征,仅服务器持有标签。本文提出一种新型VFL后门攻击:(i)不依赖服务器的梯度信息;(ii)考虑多个攻击者之间的潜在合谋以完成样本选择和触发器嵌入。攻击者使用增强度量学习的变分自编码器训练本地标签推断模型,通过对抗者图拓扑的共识机制决定污染数据点。进一步提出触发器跨攻击者分裂策略,并采用强度导向的植入方案引导服务器偏向触发器。收敛性分析揭示了后门扰动对VFL的影响,表现为模型的平稳性间隙,实验证实该现象。实验对比近期主流后门攻击方法,结果表明本方法在相同主任务性能下取得更高攻击成功率,且验证了合谋对攻击效果的显著提升。

原文摘要 · Abstract (English)

Federated learning (FL) is vulnerable to backdoor attacks, where adversaries alter model behavior on target classification labels by embedding triggers into data samples. While these attacks have received considerable attention in horizontal FL, they are less understood for vertical FL (VFL), where devices hold different features of the samples, and only the server holds the labels. In this work, we propose a novel backdoor attack on VFL which (i) does not rely on gradient information from the server and (ii) considers potential collusion among multiple adversaries for sample selection and trigger embedding. Our label inference model augments variational autoencoders with metric learning, which adversaries can train locally. A consensus process over the adversary graph topology determines which datapoints to poison. We further propose methods for trigger splitting across the adversaries, with an intensity-based implantation scheme skewing the server towards the trigger. Our convergence analysis reveals the impact of backdoor perturbations on VFL indicated by a stationarity gap for the trained model, which we verify empirically as well. We conduct experiments comparing our attack with recent backdoor VFL approaches, finding that ours obtains significantly higher success rates for the same main task performance despite not using server information. Additionally, our results verify the impact of collusion on attack performance.

联邦学习后门攻击垂直联邦安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。