arXiv:2501.17396cs.CRcs.DC2025-01被引 17

提出针对联邦遗忘的新型攻击与防御方法,保障模型安全清除

Poisoning Attacks and Defenses to Federated Unlearning

  • 恶意客户端在遗忘阶段发送精心设计的更新以维持污染
  • 新攻击能有效破坏现有遗忘方法,使模型仍含毒
  • 提出可证明鲁棒的防御框架,确保遗忘后模型如从头训练

联邦学习允许多个客户端在服务器协助下协同训练全局模型,但其分布式特性易受投毒攻击:恶意客户端通过发送有害本地模型更新来破坏全局模型。为在识别出恶意客户端后从污染模型中恢复准确模型,联邦遗忘被提出。然而,当前研究多关注遗忘的效率与效果,忽视其安全挑战。本文首次提出针对联邦遗忘的投毒攻击BadUnlearn:恶意客户端在遗忘过程中向服务器发送特定设计的本地更新,以确保遗忘后的模型仍被污染。为应对该威胁,我们提出可证明鲁棒的联邦遗忘框架UnlearnGuard,其核心思想是服务器在遗忘过程中估计客户端的本地更新,并采用过滤策略验证估计准确性。理论上,我们证明通过UnlearnGuard遗忘的模型与从头训练所得模型高度接近。实验上,我们表明BadUnlearn能有效破坏现有遗忘方法,而UnlearnGuard对投毒攻击保持安全。

原文摘要 · Abstract (English)

Federated learning allows multiple clients to collaboratively train a global model with the assistance of a server. However, its distributed nature makes it susceptible to poisoning attacks, where malicious clients can compromise the global model by sending harmful local model updates to the server. To unlearn an accurate global model from a poisoned one after identifying malicious clients, federated unlearning has been introduced. Yet, current research on federated unlearning has primarily concentrated on its effectiveness and efficiency, overlooking the security challenges it presents. In this work, we bridge the gap via proposing BadUnlearn, the first poisoning attacks targeting federated unlearning. In BadUnlearn, malicious clients send specifically designed local model updates to the server during the unlearning process, aiming to ensure that the resulting unlearned model remains poisoned. To mitigate these threats, we propose UnlearnGuard, a robust federated unlearning framework that is provably robust against both existing poisoning attacks and our BadUnlearn. The core concept of UnlearnGuard is for the server to estimate the clients' local model updates during the unlearning process and employ a filtering strategy to verify the accuracy of these estimations. Theoretically, we prove that the model unlearned through UnlearnGuard closely resembles one obtained by train-from-scratch. Empirically, we show that BadUnlearn can effectively corrupt existing federated unlearning methods, while UnlearnGuard remains secure against poisoning attacks.

联邦学习投毒攻击模型遗忘安全防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。