发现排序联邦学习中存在易被攻击的脆弱边,提出新型高效攻击方法。
Not All Edges are Equally Robust: Evaluating the Robustness of Ranking-Based Federated Learning
- 通过理论分析定位每层中最脆弱的边,构建针对性攻击策略。
- 在基准数据集上实现53.23%攻击成功率,比现有方法强3.7倍。
- 揭示排序联邦学习的安全缺陷,适合关注系统安全的研究者参考。
联邦排序学习(FRL)是一种通信高效且抗中毒攻击的先进联邦学习框架,其通过使用离散排名替代梯度更新,显著降低通信开销并限制恶意更新空间;同时,服务器端采用多数投票机制确定全局排名,使单个客户端贡献仅相当于一票,从而提升可扩展性。然而,我们的分析发现,FRL并非天然鲁棒,某些特定边在各层中尤为脆弱。通过理论研究,我们证明了这些脆弱边的存在,并建立了每层中识别它们的下界与上界。基于此,我们提出一种新型局部模型中毒攻击——脆弱边操纵(VEM)攻击,该方法聚焦于每层中最脆弱的边,利用优化策略最大化攻击效果。在多个基准数据集上的大量实验表明,该攻击整体攻击影响达53.23%,相比现有方法提升3.7倍。研究结果揭示了基于排序的联邦学习系统中的重大安全隐患,凸显了开发新型鲁棒联邦学习框架的紧迫性。
原文摘要 · Abstract (English)
Federated Ranking Learning (FRL) is a state-of-the-art FL framework that stands out for its communication efficiency and resilience to poisoning attacks. It diverges from the traditional FL framework in two ways: 1) it leverages discrete rankings instead of gradient updates, significantly reducing communication costs and limiting the potential space for malicious updates, and 2) it uses majority voting on the server side to establish the global ranking, ensuring that individual updates have minimal influence since each client contributes only a single vote. These features enhance the system's scalability and position FRL as a promising paradigm for FL training. However, our analysis reveals that FRL is not inherently robust, as certain edges are particularly vulnerable to poisoning attacks. Through a theoretical investigation, we prove the existence of these vulnerable edges and establish a lower bound and an upper bound for identifying them in each layer. Based on this finding, we introduce a novel local model poisoning attack against FRL, namely the Vulnerable Edge Manipulation (VEM) attack. The VEM attack focuses on identifying and perturbing the most vulnerable edges in each layer and leveraging an optimization-based approach to maximize the attack's impact. Through extensive experiments on benchmark datasets, we demonstrate that our attack achieves an overall 53.23% attack impact and is 3.7x more impactful than existing methods. Our findings highlight significant vulnerabilities in ranking-based FL systems and underline the urgency for the development of new robust FL frameworks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。