arXiv:2505.06335cs.LGcs.AI2025-05

攻击者通过操纵客户端观测,远程触发服务器内存位翻转,破坏联邦学习系统安全。

Remote Rowhammer Attack using Adversarial Observations on Federated Learning Clients

  • 利用强化学习操控客户端观测,诱导服务器高频重复内存更新。
  • 在语音识别系统中实现约70%的重复更新率,成功引发内存位翻转。
  • 无需服务器权限,为联邦学习硬件安全提供新攻击视角,适合安全研究者关注。

联邦学习(FL)允许多个并行代理同时进行全局学习,使大规模语言模型等新兴AI可在人口多样性数据上训练。其高效性依赖于服务器端的稀疏梯度更新和远程直接内存访问。现有研究多聚焦于保护边缘客户端或通信链路中的数据隐私,对面向服务器的客户端攻击关注较少,因普遍认为大量客户端可提供韧性。本文首次证明,通过攻击特定客户端使其在服务器端产生高频重复内存更新,可远程发起行翻转(Rowhammer)攻击。攻击者无需服务器后门,仅需使用强化学习(RL)代理,通过操纵客户端传感器观测,最大化服务器重复内存更新频率。实验基于大规模稀疏更新的联邦语音识别(ASR)系统,攻击代理实现约70%的重复更新率(RUR),有效诱发服务器DRAM位翻转。后果包括学习过程中断或权限提升,揭示了联邦学习在硬件层面的安全风险,为后续防御策略与硬件设计提供研究方向。

原文摘要 · Abstract (English)

Federated Learning (FL) has the potential for simultaneous global learning amongst a large number of parallel agents, enabling emerging AI such as LLMs to be trained across demographically diverse data. Central to this being efficient is the ability for FL to perform sparse gradient updates and remote direct memory access at the central server. Most of the research in FL security focuses on protecting data privacy at the edge client or in the communication channels between the client and server. Client-facing attacks on the server are less well investigated as the assumption is that a large collective of clients offer resilience. Here, we show that by attacking certain clients that lead to a high frequency repetitive memory update in the server, we can remote initiate a rowhammer attack on the server memory. For the first time, we do not need backdoor access to the server, and a reinforcement learning (RL) attacker can learn how to maximize server repetitive memory updates by manipulating the client's sensor observation. The consequence of the remote rowhammer attack is that we are able to achieve bit flips, which can corrupt the server memory. We demonstrate the feasibility of our attack using a large-scale FL automatic speech recognition (ASR) systems with sparse updates, our adversarial attacking agent can achieve around 70% repeated update rate (RUR) in the targeted server model, effectively inducing bit flips on server DRAM. The security implications are that can cause disruptions to learning or may inadvertently cause elevated privilege. This paves the way for further research on practical mitigation strategies in FL and hardware design.

联邦学习内存安全强化学习位翻转

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。