arXiv:2504.12875cs.LG2025-04被引 2

提出新型协作后门攻击,仅用少量被攻陷客户端即可隐蔽污染联邦学习模型。

A Client-level Assessment of Collaborative Backdoor Poisoning in Non-IID Federated Learning

  • 设计协同后门攻击CollaPois,通过共享受感染模型生成恶意梯度
  • 在非独立同分布数据下仍能隐蔽触发后门,且对正常数据性能无明显影响
  • 适用于低比例攻陷客户端场景,特别威胁本地数据相似的客户端

联邦学习(FL)允许多个客户端使用分散的私有数据协作训练模型。尽管现有防御机制对基础投毒攻击具有一定鲁棒性,但本研究揭示了客户端间非独立同分布(non-IID)数据带来的新漏洞。为此,我们提出一种新型协作后门攻击方法CollaPois:将一个预先训练好的带木马模型分发给一组被攻陷的客户端,这些客户端协同生成恶意梯度,使联邦模型持续收敛至围绕木马模型的低损失区域。该攻击在良性客户端数据分布多样、局部梯度分散时效果更显著。与现有攻击相比,CollaPois仅需少量被攻陷客户端即可达成目标,并且不引起合法数据性能的明显下降,从而实现隐蔽运行,绕过先进鲁棒性算法的检测。理论分析与多基准数据集实验表明,该攻击优于当前最优后门攻击,在客户端数据分布差异大的场景下依然有效。此外,当本地数据与攻陷客户端相近时,感染风险更高。

原文摘要 · Abstract (English)

Federated learning (FL) enables collaborative model training using decentralized private data from multiple clients. While FL has shown robustness against poisoning attacks with basic defenses, our research reveals new vulnerabilities stemming from non-independent and identically distributed (non-IID) data among clients. These vulnerabilities pose a substantial risk of model poisoning in real-world FL scenarios. To demonstrate such vulnerabilities, we develop a novel collaborative backdoor poisoning attack called CollaPois. In this attack, we distribute a single pre-trained model infected with a Trojan to a group of compromised clients. These clients then work together to produce malicious gradients, causing the FL model to consistently converge towards a low-loss region centered around the Trojan-infected model. Consequently, the impact of the Trojan is amplified, especially when the benign clients have diverse local data distributions and scattered local gradients. CollaPois stands out by achieving its goals while involving only a limited number of compromised clients, setting it apart from existing attacks. Also, CollaPois effectively avoids noticeable shifts or degradation in the FL model's performance on legitimate data samples, allowing it to operate stealthily and evade detection by advanced robust FL algorithms. Thorough theoretical analysis and experiments conducted on various benchmark datasets demonstrate the superiority of CollaPois compared to state-of-the-art backdoor attacks. Notably, CollaPois bypasses existing backdoor defenses, especially in scenarios where clients possess diverse data distributions. Moreover, the results show that CollaPois remains effective even when involving a small number of compromised clients. Notably, clients whose local data is closely aligned with compromised clients experience higher risks of backdoor infections.

联邦学习后门攻击非独立同分布隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。