用自然数据特征做触发器,攻破个性化联邦学习的后门防御
Bad-PFL: Exploring Backdoor Attacks against Personalized Federated Learning
- 用自然数据特征作触发器,让后门在个性化模型中长期存活
- 触发器与模型互训增强,攻击成功率超现有方法
- 对主流防御机制仍有效,适合研究安全与对抗攻击者
数据异构性和后门攻击是联邦学习面临的主要挑战。个性化联邦学习(PFL)使每个客户端可维护私有个性化模型以适应本地知识,但传统联邦学习易受后门攻击。尽管近年研究表明PFL可能免疫此类攻击,本文揭示:人工设计的触发器难以在个性化模型中留存。为此,我们提出Bad-PFL,采用自然数据特征作为触发器。只要模型在自然数据上训练,就会自动嵌入对应后门,确保其在个性化模型中持久存在。此外,触发器与模型通过互训强化,进一步提升后门稳定性与攻击效果。大规模实验在三个基准数据集上验证,本攻击在多种PFL方法中表现优异,即使面对先进防御机制也具高成功率。
原文摘要 · Abstract (English)
Data heterogeneity and backdoor attacks rank among the most significant challenges facing federated learning (FL). For data heterogeneity, personalized federated learning (PFL) enables each client to maintain a private personalized model to cater to client-specific knowledge. Meanwhile, vanilla FL has proven vulnerable to backdoor attacks. However, recent advancements in PFL community have demonstrated a potential immunity against such attacks. This paper explores this intersection further, revealing that existing federated backdoor attacks fail in PFL because backdoors about manually designed triggers struggle to survive in personalized models. To tackle this, we design Bad-PFL, which employs features from natural data as our trigger. As long as the model is trained on natural data, it inevitably embeds the backdoor associated with our trigger, ensuring its longevity in personalized models. Moreover, our trigger undergoes mutual reinforcement training with the model, further solidifying the backdoor's durability and enhancing attack effectiveness. The large-scale experiments across three benchmark datasets demonstrate the superior performance of our attack against various PFL methods, even when equipped with state-of-the-art defense mechanisms.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。