arXiv:2503.23288cs.LGcs.AI2025-03被引 4

针对非独立同分布数据下的模型投毒攻击,提出双通道防御机制。

Two Heads Are Better than One: Model-Weight and Latent-Space Analysis for Federated Learning on Non-iid Data against Poisoning Attacks

  • 结合模型权重与潜在空间分析,互补提升防御能力
  • 在多种非独立同分布场景下,显著优于现有最先进方法
  • 轻量无监督设计,适合实际联邦学习部署

联邦学习允许远程客户端在不共享原始数据的前提下联合训练全局模型,但其分布式特性使其易受模型投毒攻击。攻击者可伪装为参与者上传任意恶意模型更新,破坏全局模型。尽管已有大量研究应对此类攻击,但多数假设客户端数据服从独立同分布(iid),而现实中数据不可避免地呈现非独立同分布(non-iid)。我们的基准评估发现,现有防御在非iid场景下普遍失效。为此,本文提出轻量、通用且无监督的新型防御方法GeminiGuard,以填补这一关键空白。核心思路源于两个观察:(1) 单一依赖模型权重或潜在空间分析的防御在应对不同类型的模型投毒攻击(MPA)及非iid场景时存在局限;(2) 模型权重与潜在空间分析在机制上差异明显但具有互补性。因此,GeminiGuard融合了创新的模型权重分析组件与定制化的潜在空间分析组件,以增强整体防御性能。实验覆盖多种设置,验证其对多种未定向和定向攻击(包括自适应攻击)的有效性。全面评估表明,GeminiGuard在各类场景下均持续优于当前最先进防御方法。

原文摘要 · Abstract (English)

Federated Learning is a popular paradigm that enables remote clients to jointly train a global model without sharing their raw data. However, FL has been shown to be vulnerable towards model poisoning attacks due to its distributed nature. Particularly, attackers acting as participants can upload arbitrary model updates that effectively compromise the global model of FL. While extensive research has been focusing on fighting against these attacks, we find that most of them assume data at remote clients are under iid while in practice they are inevitably non-iid. Our benchmark evaluations reveal that existing defenses generally fail to live up to their reputation when applied to various non-iid scenarios. In this paper, we propose a novel approach, GeminiGuard, that aims to address such a significant gap. We design GeminiGuard to be lightweight, versatile, and unsupervised so that it aligns well with the practical requirements of deploying such defenses. The key challenge from non-iids is that they make benign model updates look more similar to malicious ones. GeminiGuard is mainly built on two fundamental observations: (1) existing defenses based on either model-weight analysis or latent-space analysis face limitations in covering different MPAs and non-iid scenarios, and (2) model-weight and latent-space analysis are sufficiently different yet potentially complementary methods as MPA defenses. We hence incorporate a novel model-weight analysis component as well as a custom latent-space analysis component in GeminiGuard, aiming to further enhance its defense performance. We conduct extensive experiments to evaluate our defense across various settings, demonstrating its effectiveness in countering multiple types of untargeted and targeted MPAs, including adaptive ones. Our comprehensive evaluations show that GeminiGuard consistently outperforms SOTA defenses under various settings.

联邦学习模型投毒非iid安全防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。