用图自编码器伪造模型更新,破坏边缘物联网联邦学习
Undermining Federated Learning Accuracy in EdgeIoT via Variational Graph Auto-Encoders
- 用对抗性图自编码器分析正常模型,生成恶意更新
- 攻击不依赖真实数据,仍能显著提高训练损失
- 适合研究联邦学习安全的工程师与攻防研究人员
边缘物联网(EdgeIoT)将移动边缘计算与物联网设备结合,实现数据就近处理,避免上传原始数据带来的带宽压力和隐私风险。联邦学习通过聚合各设备本地训练的模型更新,实现协同学习。然而,该机制依赖于来自多个物联网设备的模型更新,易受恶意实体攻击。本文提出一种新型攻击方法——数据无关的模型操纵攻击,无需使用设备训练数据,而是利用对抗性变分图自编码器(AV-GAE)分析通信中截获的正常模型更新,识别并利用良性模型与其训练数据特征间的结构关系,通过操纵这些关联关系,最大化联邦学习系统的训练损失,严重削弱其有效性。
原文摘要 · Abstract (English)
EdgeIoT represents an approach that brings together mobile edge computing with Internet of Things (IoT) devices, allowing for data processing close to the data source. Sending source data to a server is bandwidth-intensive and may compromise privacy. Instead, federated learning allows each device to upload a shared machine-learning model update with locally processed data. However, this technique, which depends on aggregating model updates from various IoT devices, is vulnerable to attacks from malicious entities that may inject harmful data into the learning process. This paper introduces a new attack method targeting federated learning in EdgeIoT, known as data-independent model manipulation attack. This attack does not rely on training data from the IoT devices but instead uses an adversarial variational graph auto-encoder (AV-GAE) to create malicious model updates by analyzing benign model updates intercepted during communication. AV-GAE identifies and exploits structural relationships between benign models and their training data features. By manipulating these structural correlations, the attack maximizes the training loss of the federated learning system, compromising its overall effectiveness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。