arXiv:2501.12123cs.CRcs.AI2025-01被引 1

提出首个非独立同分布下同时防御恶意与后门攻击的联邦学习防护方法。

FL-CLEANER: byzantine and backdoor defense by CLustering Errors of Activation maps in Non-iid fedErated leaRning

  • 通过激活图重建误差计算客户端可信度,结合条件变分自编码器建模。
  • 在非独立同分布场景下,误判正常客户端率低于1%,对抗攻击效果显著。
  • 适合高隐私要求、数据异构的现实联邦学习系统使用。

联邦学习(FL)允许客户端在保护数据隐私的前提下协同训练全局模型,但易受污染攻击。现有防御机制假设客户端数据独立同分布(IID),在真实数据非独立同分布(non-IID)场景下失效。本文提出FL-CLEANER,首个可在non-IID联邦学习环境中同时过滤拜占庭及后门攻击者模型更新的防御方法。其创新性体现在两方面:首先,基于每个客户端对特定触发集的模型激活图重建误差,构建客户端置信度评分,重建误差通过一种新型服务器端策略训练的条件变分自编码器获取;其次,提出原创的专用信任传播算法,依据历史评分构建良性客户端聚类并标记潜在攻击者。在MNIST和FashionMNIST数据集上的实验表明,FL-CLEANER在non-IID场景下对拜占庭攻击及部分前沿后门攻击均具高效防御能力;即使无攻击时,良性客户端误判率也低于1%,性能优于现有主流防御方法。

原文摘要 · Abstract (English)

Federated Learning (FL) enables clients to collaboratively train a global model using their local datasets while reinforcing data privacy, but it is prone to poisoning attacks. Existing defense mechanisms assume that clients' data are independent and identically distributed (IID), making them ineffective in real-world applications where data are non-IID. This paper presents FL-CLEANER, the first defense capable of filtering both byzantine and backdoor attackers' model updates in a non-IID FL environment. The originality of FL-CLEANER is twofold. First, it relies on a client confidence score derived from the reconstruction errors of each client's model activation maps for a given trigger set, with reconstruction errors obtained by means of a Conditional Variational Autoencoder trained according to a novel server-side strategy. Second, it uses an original ad-hoc trust propagation algorithm we propose. Based on previous client scores, it allows building a cluster of benign clients while flagging potential attackers. Experimental results on the datasets MNIST and FashionMNIST demonstrate the efficiency of FL-CLEANER against Byzantine attackers as well as to some state-of-the-art backdoors in non-IID scenarios; it achieves a close-to-zero (<1%) benign client misclassification rate, even in the absence of an attack, and achieves strong performance compared to state of the art defenses.

联邦学习安全防御非独立同分布后门攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。