用滑模控制实现精准可控的联邦学习投毒攻击
Performance Guaranteed Poisoning Attacks in Federated Learning: A Sliding Mode Approach
- 结合滑模控制理论设计可控投毒机制
- 可精确将全局模型准确率降至预设目标(如10%)
- 仅需少量恶意客户端,隐蔽性强适合隐秘攻击
联邦学习中,本地数据与更新的篡改——即投毒攻击——是其协作特性带来的主要威胁。现有攻击多导致服务拒绝(DoS),而本文提出新型攻击方案FedSA,旨在以微妙且受控的方式引入特定程度的污染。该方法融合鲁棒非线性控制中的滑模控制(SMC)理论,通过操纵恶意客户端的更新,使全局模型逐步趋于受损状态,以可控且不易察觉的速度实现目标。同时,利用其鲁棒控制特性,可精确调控收敛边界,使攻击者能将中毒模型的全局准确率设定为任意期望水平。实验表明,FedSA可在较少恶意客户端下精准达成预设准确率,兼具高隐蔽性与可调的学习率。
原文摘要 · Abstract (English)
Manipulation of local training data and local updates, i.e., the poisoning attack, is the main threat arising from the collaborative nature of the federated learning (FL) paradigm. Most existing poisoning attacks aim to manipulate local data/models in a way that causes denial-of-service (DoS) issues. In this paper, we introduce a novel attack method, named Federated Learning Sliding Attack (FedSA) scheme, aiming at precisely introducing the extent of poisoning in a subtle controlled manner. It operates with a predefined objective, such as reducing global model's prediction accuracy by 10%. FedSA integrates robust nonlinear control-Sliding Mode Control (SMC) theory with model poisoning attacks. It can manipulate the updates from malicious clients to drive the global model towards a compromised state, achieving this at a controlled and inconspicuous rate. Additionally, leveraging the robust control properties of FedSA allows precise control over the convergence bounds, enabling the attacker to set the global accuracy of the poisoned model to any desired level. Experimental results demonstrate that FedSA can accurately achieve a predefined global accuracy with fewer malicious clients while maintaining a high level of stealth and adjustable learning rates.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。