arXiv:2501.15005cs.LG2025-01被引 1

提出动态聚类防御的分布式后门攻击,提升不同网络位置下的攻击成功率。

DBA-DFL: Towards Distributed Backdoor Attacks with Network Detection in Decentralized Federated Learning

  • 通过预测攻击者间距离实现网络结构检测并分组
  • 在不同集群中动态注入全局模式分解出的局部特征
  • 在多个去中心化框架中优于集中式攻击和原始方法

分布式后门攻击(DBA)在集中式联邦学习中已表现出高于集中式攻击的成功率。然而,其在去中心化联邦学习中的效果尚未被研究。本文实证表明,在直接应用于去中心化联邦学习时,攻击成功率取决于攻击者在网络拓扑中的分布情况。由于攻击者无法自主选择位置,本文旨在实现无论攻击者如何分布都能保持高成功率。具体地,我们首先设计一种方法,通过预测任意两个攻击者之间的距离来探测网络结构;随后根据距离对攻击者进行聚类;最后提出一种算法,将全局模式分解出的局部模式动态嵌入到各簇中的攻击者。我们在基准数据集上进行了全面的实验验证,结果表明,该方法在多种去中心化框架下,均优于集中式攻击与原始的分布式攻击。

原文摘要 · Abstract (English)

Distributed backdoor attacks (DBA) have shown a higher attack success rate than centralized attacks in centralized federated learning (FL). However, it has not been investigated in the decentralized FL. In this paper, we experimentally demonstrate that, while directly applying DBA to decentralized FL, the attack success rate depends on the distribution of attackers in the network architecture. Considering that the attackers can not decide their location, this paper aims to achieve a high attack success rate regardless of the attackers' location distribution. Specifically, we first design a method to detect the network by predicting the distance between any two attackers on the network. Then, based on the distance, we organize the attackers in different clusters. Lastly, we propose an algorithm to \textit{dynamically} embed local patterns decomposed from a global pattern into the different attackers in each cluster. We conduct a thorough empirical investigation and find that our method can, in benchmark datasets, outperform both centralized attacks and naive DBA in different decentralized frameworks.

后门攻击联邦学习去中心化动态注入

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。