通过知识蒸馏识别良性行为,抵御联邦学习中的隐蔽后门攻击
DROP: Poison Dilution via Knowledge Distillation for Federated Learning
- 用聚类与活动追踪结合知识蒸馏,提取客户端良性行为特征
- 在低数据污染率和多变恶意客户端比例下仍保持高鲁棒性
- 适合应对非独立同分布数据场景下的复杂攻击,适用于安全敏感的联邦学习系统
联邦学习易受恶意客户端的对抗性操纵,攻击者可通过注入污染更新影响全局模型行为。现有防御方法虽有进展,但在不同学习与攻击配置下难以防范目标型后门攻击。为此,本文提出DROP(基于知识蒸馏的中毒削减),融合聚类与活动追踪技术,通过知识蒸馏提取客户端良性行为,以应对低数据污染率及多样恶意客户端比例下的隐蔽攻击。大量实验表明,本方法在多种学习配置下均优于现有防御机制。最后,我们在非独立同分布(non-IID)客户端数据分布的挑战性设置下评估了现有方法与本方法,揭示了在此场景下设计鲁棒联邦学习防御的难题。
原文摘要 · Abstract (English)
Federated Learning is vulnerable to adversarial manipulation, where malicious clients can inject poisoned updates to influence the global model's behavior. While existing defense mechanisms have made notable progress, they fail to protect against adversaries that aim to induce targeted backdoors under different learning and attack configurations. To address this limitation, we introduce DROP (Distillation-based Reduction Of Poisoning), a novel defense mechanism that combines clustering and activity-tracking techniques with extraction of benign behavior from clients via knowledge distillation to tackle stealthy adversaries that manipulate low data poisoning rates and diverse malicious client ratios within the federation. Through extensive experimentation, our approach demonstrates superior robustness compared to existing defenses across a wide range of learning configurations. Finally, we evaluate existing defenses and our method under the challenging setting of non-IID client data distribution and highlight the challenges of designing a resilient FL defense in this setting.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。