通过噪声激活分析识别并剔除联邦学习中的恶意客户端
FedNIA: Noise-Induced Activation Analysis for Mitigating Data Poisoning in FL
- 向客户端模型注入噪声,分析各层激活模式
- 在多客户端攻击下仍能有效防御样本污染、标签翻转等攻击
- 无需中央测试数据,适合实际部署的隐私敏感场景
联邦学习系统正面临数据投毒攻击的严峻威胁,恶意客户端通过提交篡改的更新来破坏全局模型。现有防御方法常依赖不切实际的假设(如需中心测试数据),或无法泛化至多种攻击类型,尤其难以应对多个恶意客户端协同攻击的情况。为此,我们提出联邦噪声诱导激活分析(FedNIA),一种新型防御框架,可在无需任何中央测试数据的前提下,识别并排除恶意客户端。FedNIA通过向客户端模型注入随机噪声输入,利用自编码器分析其分层激活模式,检测出数据投毒的异常行为。该方法可有效防御多种攻击类型,包括样本投毒、标签翻转和后门攻击,即使在多个攻击节点共谋的复杂场景中也表现稳健。在非独立同分布的联邦数据集上的实验结果验证了其有效性与鲁棒性,凸显其作为提升联邦学习安全性的基础性方案的潜力。
原文摘要 · Abstract (English)
Federated learning systems are increasingly threatened by data poisoning attacks, where malicious clients compromise global models by contributing tampered updates. Existing defenses often rely on impractical assumptions, such as access to a central test dataset, or fail to generalize across diverse attack types, particularly those involving multiple malicious clients working collaboratively. To address this, we propose Federated Noise-Induced Activation Analysis (FedNIA), a novel defense framework to identify and exclude adversarial clients without relying on any central test dataset. FedNIA injects random noise inputs to analyze the layerwise activation patterns in client models leveraging an autoencoder that detects abnormal behaviors indicative of data poisoning. FedNIA can defend against diverse attack types, including sample poisoning, label flipping, and backdoors, even in scenarios with multiple attacking nodes. Experimental results on non-iid federated datasets demonstrate its effectiveness and robustness, underscoring its potential as a foundational approach for enhancing the security of federated learning systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。