arXiv:2501.11054cs.LGcs.CR2025-01被引 3

研究联邦学习中随时间变化的攻击对模型的影响,发现后期攻击危害更大。

Temporal Analysis of Adversarial Attacks in Federated Learning

  • 通过模拟持续或后期活跃的恶意客户端进行攻击
  • 后期攻击使模型性能显著下降,部分场景下准确率降低超20%
  • 适合关注联邦学习安全性的研究人员和系统设计者

本文实验分析了多种联邦学习(FL)系统在对抗性客户端存在下的鲁棒性。结果表明,时间相关的攻击会显著影响测试模型的性能,尤其当攻击者在整个训练过程或后期轮次中持续活跃时。我们考察了多项经典学习模型,包括多元逻辑回归(MLR)、随机森林、XGBoost、支持向量分类器(SVC),以及多层感知机(MLP)、卷积神经网络(CNN)、循环神经网络(RNN)和长短期记忆网络(LSTM)。实验揭示了时间攻击的有效性,并强调需发展更鲁棒的防御策略。同时初步评估了聚合算法中的异常检测机制的防御效果。

原文摘要 · Abstract (English)

In this paper, we experimentally analyze the robustness of selected Federated Learning (FL) systems in the presence of adversarial clients. We find that temporal attacks significantly affect model performance in the FL models tested, especially when the adversaries are active throughout or during the later rounds. We consider a variety of classic learning models, including Multinominal Logistic Regression (MLR), Random Forest, XGBoost, Support Vector Classifier (SVC), as well as various Neural Network models including Multilayer Perceptron (MLP), Convolution Neural Network (CNN), Recurrent Neural Network (RNN), and Long Short-Term Memory (LSTM). Our results highlight the effectiveness of temporal attacks and the need to develop strategies to make the FL process more robust against such attacks. We also briefly consider the effectiveness of defense mechanisms, including outlier detection in the aggregation algorithm.

联邦学习对抗攻击安全防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。