arXiv:2502.04890cs.LG2025-02AAAI被引 5

发现梯度偏斜现象,让恶意攻击者骗过联邦学习防御机制

Exploit Gradient Skewness to Circumvent Byzantine Defenses for Federated Learning

  • 利用数据异构导致的梯度偏斜,定位诚实梯度聚集区
  • 在偏斜区域内构造恶意梯度,使其伪装成正常梯度
  • 在三个基准数据集上验证攻击有效,突破现有防御

联邦学习(FL)因其易受拜占庭攻击而闻名。当前多数拜占庭防御方法共享一个共性假设:梯度分布密集区域更可能包含诚实梯度。然而本文首次发现一种新现象——梯度偏斜:由于数据异构,大量诚实梯度会偏离最优梯度(即诚实梯度的均值)。该偏斜现象使拜占庭梯度可隐藏于密集分布的偏斜梯度中,导致防御机制误判其为诚实梯度。基于此,我们提出新型偏斜感知攻击STRIKE:首先搜索偏斜梯度区域,再在其中构造拜占庭梯度。在三个基准数据集上的实验验证了该攻击的有效性。

原文摘要 · Abstract (English)

Federated Learning (FL) is notorious for its vulnerability to Byzantine attacks. Most current Byzantine defenses share a common inductive bias: among all the gradients, the densely distributed ones are more likely to be honest. However, such a bias is a poison to Byzantine robustness due to a newly discovered phenomenon in this paper - gradient skew. We discover that a group of densely distributed honest gradients skew away from the optimal gradient (the average of honest gradients) due to heterogeneous data. This gradient skew phenomenon allows Byzantine gradients to hide within the densely distributed skewed gradients. As a result, Byzantine defenses are confused into believing that Byzantine gradients are honest. Motivated by this observation, we propose a novel skew-aware attack called STRIKE: first, we search for the skewed gradients; then, we construct Byzantine gradients within the skewed gradients. Experiments on three benchmark datasets validate the effectiveness of our attack

联邦学习拜占庭攻击梯度偏斜安全攻防

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。