提出新型协同投毒攻击,专攻去中心化联邦学习的模型差异漏洞。
DMPA: Model Poisoning Attacks on Decentralized Federated Learning for Model Differences
- 利用多恶意客户端模型差异设计协同投毒策略
- 在多个数据集上性能超越现有最先进攻击方法
- 适合研究联邦学习安全与对抗攻击的学者参考
联邦学习(FL)作为一种重要的隐私保护机器学习范式受到广泛关注。去中心化联邦学习(DFL)摒弃传统集中式服务器架构,提升了系统的鲁棒性与可扩展性。然而,这些优势也带来了新的安全隐患,使恶意参与者更容易实施对抗性攻击,尤其是模型投毒攻击。在模型投毒攻击中,恶意参与者通过生成并传播受损模型来降低良性模型的性能。现有研究主要集中在集中式联邦学习(CFL)中对全局模型的破坏,而对去中心化联邦学习(DFL)的研究相对不足。为填补这一空白,本文提出一种创新的模型投毒攻击方法DMPA。该方法通过计算多个恶意客户端模型的差异特征,获得最有效的投毒策略,从而实现多方协同攻击。实验在多个数据集上验证了该方法的有效性,结果表明DMPA在性能上持续优于现有最先进的联邦学习模型投毒攻击策略。
原文摘要 · Abstract (English)
Federated learning (FL) has garnered significant attention as a prominent privacy-preserving Machine Learning (ML) paradigm. Decentralized FL (DFL) eschews traditional FL's centralized server architecture, enhancing the system's robustness and scalability. However, these advantages of DFL also create new vulnerabilities for malicious participants to execute adversarial attacks, especially model poisoning attacks. In model poisoning attacks, malicious participants aim to diminish the performance of benign models by creating and disseminating the compromised model. Existing research on model poisoning attacks has predominantly concentrated on undermining global models within the Centralized FL (CFL) paradigm, while there needs to be more research in DFL. To fill the research gap, this paper proposes an innovative model poisoning attack called DMPA. This attack calculates the differential characteristics of multiple malicious client models and obtains the most effective poisoning strategy, thereby orchestrating a collusive attack by multiple participants. The effectiveness of this attack is validated across multiple datasets, with results indicating that the DMPA approach consistently surpasses existing state-of-the-art FL model poisoning attack strategies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。