构建统一基准评估联邦学习中的数据与模型投毒攻击防御效果
SoK: Benchmarking Poisoning Attacks and Defenses in Federated Learning
- 提出FLOpoison基准,支持15种攻击与17种防御的系统评估
- 在多种算法和数据异构条件下验证防御有效性并发现协同弱点
- 揭示攻防互斥现象,为未来防御设计提供关键指导
联邦学习(FL)可在保护数据隐私的前提下实现协作建模,但其去中心化特性使其易受客户端数据投毒攻击(DPAs)和模型投毒攻击(MPAs)影响,导致全局模型性能下降。尽管已有众多防御方案声称有效,但其评估常孤立进行,攻击策略有限,且忽视了防御对两类攻击的联合有效性,导致该领域研究碎片化。本文旨在建立统一基准与分析框架,厘清DPAs与MPAs的差异。我们提出系统化的投毒攻击与防御策略分类,分析其设计、优势与局限。进一步,在不同联邦学习算法和数据异构性条件下开展统一对比评估,验证各类防御的独立与协同有效性,并提炼出设计原则与未来研究方向。同时,我们构建了高可扩展性的基准工具FLPoison,支持15种代表性攻击与17种防御策略的评估,代码已开源。
原文摘要 · Abstract (English)
Federated learning (FL) enables collaborative model training while preserving data privacy, but its decentralized nature exposes it to client-side data poisoning attacks (DPAs) and model poisoning attacks (MPAs) that degrade global model performance. While numerous proposed defenses claim substantial effectiveness, their evaluation is typically done in isolation with limited attack strategies, raising concerns about their validity. Additionally, existing studies overlook the mutual effectiveness of defenses against both DPAs and MPAs, causing fragmentation in this field. This paper aims to provide a unified benchmark and analysis of defenses against DPAs and MPAs, clarifying the distinction between these two similar but slightly distinct domains. We present a systematic taxonomy of poisoning attacks and defense strategies, outlining their design, strengths, and limitations. Then, a unified comparative evaluation across FL algorithms and data heterogeneity is conducted to validate their individual and mutual effectiveness and derive key insights for design principles and future research. Along with the analysis, we frame our work to a unified benchmark, FLPoison, with high modularity and scalability to evaluate 15 representative poisoning attacks and 17 defense strategies, facilitating future research in this domain. Code is available at https://github.com/vio1etus/FLPoison.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。