针对联邦学习无线网络的智能攻击与防御,提升能效同时增强安全性。
Intelligent Attacks and Defense Methods in Federated Learning-enabled Energy-Efficient Wireless Networks
- 用深度强化学习优化基站休眠以提升能效。
- 提出两种新型模型投毒攻击:GAN增强型与正则化型。
- 设计自编码器与知识蒸馏防御机制,识别并过滤恶意节点。
联邦学习(FL)在无线网络中具有分布式实现的优势,但其分布式特性也增加了遭受恶意攻击的风险,尤其在动态无线环境和非独立同分布(non-IID)数据条件下,攻击难以被检测。本文构建了一个基于联邦深度强化学习的小区休眠控制场景,以提升网络能效。针对学习驱动的方案,提出了两种智能攻击模型:基于生成对抗网络(GAN)的模型投毒攻击和基于正则化的模型投毒攻击。作为应对,设计了两种防御方法:自编码器基防御通过识别恶意参与方,仅聚合良性本地模型参数;知识蒸馏(KD)基防御通过控制全局模型与本地模型间知识传递,保护模型免受攻击。实验验证了所提方法的有效性。
原文摘要 · Abstract (English)
Federated learning (FL) is a promising technique for learning-based functions in wireless networks, thanks to its distributed implementation capability. On the other hand, distributed learning may increase the risk of exposure to malicious attacks where attacks on a local model may spread to other models by parameter exchange. Meanwhile, such attacks can be hard to detect due to the dynamic wireless environment, especially considering local models can be heterogeneous with non-independent and identically distributed (non-IID) data. Therefore, it is critical to evaluate the effect of malicious attacks and develop advanced defense techniques for FL-enabled wireless networks. In this work, we introduce a federated deep reinforcement learning-based cell sleep control scenario that enhances the energy efficiency of the network. We propose multiple intelligent attacks targeting the learning-based approach and we propose defense methods to mitigate such attacks. In particular, we have designed two attack models, generative adversarial network (GAN)-enhanced model poisoning attack and regularization-based model poisoning attack. As a counteraction, we have proposed two defense schemes, autoencoder-based defense, and knowledge distillation (KD)-enabled defense. The autoencoder-based defense method leverages an autoencoder to identify the malicious participants and only aggregate the parameters of benign local models during the global aggregation, while KD-based defense protects the model from attacks by controlling the knowledge transferred between the global model and local models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。