arXiv:2505.09983cs.CRcs.LG2025-05中稿 · IEEE Codit 2025被引 1

恶意客户端用虚拟节点放大攻击,低成本实现联邦学习中毒

Sybil-based Virtual Data Poisoning Attacks in Federated Learning

  • 通过生成虚拟节点扩大攻击影响,降低计算开销
  • 在非独立同分布数据下仍能成功获取全局目标模型
  • 适配在线本地、在线全局和离线三种攻击场景

联邦学习易受恶意敌手的中毒攻击。现有方法通常成本较高,难以有效实施。为此,本文提出一种基于Sybil的虚拟数据中毒攻击:恶意客户端生成多个虚拟节点,以增强中毒模型的影响。为降低神经网络计算复杂度,我们设计了一种基于梯度匹配的虚拟数据生成方法,并提出了三种适用于在线本地、在线全局及离线场景的目标模型获取方案。仿真结果表明,该方法在非独立同分布(non-IID)数据条件下仍能有效获取全局目标模型,性能优于其他攻击算法。

原文摘要 · Abstract (English)

Federated learning is vulnerable to poisoning attacks by malicious adversaries. Existing methods often involve high costs to achieve effective attacks. To address this challenge, we propose a sybil-based virtual data poisoning attack, where a malicious client generates sybil nodes to amplify the poisoning model's impact. To reduce neural network computational complexity, we develop a virtual data generation method based on gradient matching. We also design three schemes for target model acquisition, applicable to online local, online global, and offline scenarios. In simulation, our method outperforms other attack algorithms since our method can obtain a global target model under non-independent uniformly distributed data.

联邦学习中毒攻击虚拟节点

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。