arXiv:2502.05211cs.CRcs.AI2025-02

揭露联邦学习防御的实验陷阱,提供系统化评估方法

Decoding FL Defenses: Systemization, Pitfalls, and Remedies

  • 按更新处理、服务器认知、防御时机三维度系统化分类防御方法
  • 发现50篇顶会论文中30%仅用鲁棒性较强的MNIST数据集
  • 提出可复现的评估建议,帮助研究者避免误判防御有效性

尽管社区已设计多种防御手段应对联邦学习中的投毒攻击,但缺乏统一的评估准则。现有防御常因实验设置中的隐蔽缺陷而产生虚假安全假象,难以实际部署。本文系统梳理了联邦学习防御的三维度框架:客户端更新的处理方式、服务器所知信息、防御实施阶段。我们深入调研50篇顶级防御论文,识别其评估设置中的共性组件,发现六类典型陷阱。例如,约30%的研究仅使用内在鲁棒的MNIST数据集,40%采用简单攻击方式,可能错误地夸大防御效果。通过三个代表性防御的重新评估,揭示这些陷阱如何导致对鲁棒性的误判,并提出具体改进建议,助力研究者构建更可靠的评估体系。

原文摘要 · Abstract (English)

While the community has designed various defenses to counter the threat of poisoning attacks in Federated Learning (FL), there are no guidelines for evaluating these defenses. These defenses are prone to subtle pitfalls in their experimental setups that lead to a false sense of security, rendering them unsuitable for practical deployment. In this paper, we systematically understand, identify, and provide a better approach to address these challenges. First, we design a comprehensive systemization of FL defenses along three dimensions: i) how client updates are processed, ii) what the server knows, and iii) at what stage the defense is applied. Next, we thoroughly survey 50 top-tier defense papers and identify the commonly used components in their evaluation setups. Based on this survey, we uncover six distinct pitfalls and study their prevalence. For example, we discover that around 30% of these works solely use the intrinsically robust MNIST dataset, and 40% employ simplistic attacks, which may inadvertently portray their defense as robust. Using three representative defenses as case studies, we perform a critical reevaluation to study the impact of the identified pitfalls and show how they lead to incorrect conclusions about robustness. We provide actionable recommendations to help researchers overcome each pitfall.

联邦学习安全防御评估漏洞实验设计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。