用良性扰动破坏后门触发依赖,提升联邦学习抗攻击能力
FedBAP: Backdoor Defense via Benign Adversarial Perturbation in Federated Learning
- 生成与后门触发器位置大小一致的扰动触发器
- 使模型对后门触发器依赖降低,攻击成功率下降超97%
- 自适应调节扰动强度,兼顾防御效果与模型性能
联邦学习在保护数据隐私的同时实现协同建模,但极易受到后门攻击。现有防御方法因忽视模型对后门触发器的过度依赖,尤其在恶意客户端比例升高时效果有限。本文提出FedBAP,通过降低模型对后门触发器的依赖来缓解攻击。首先设计扰动触发器生成机制,使其在位置和尺寸上精确匹配后门触发器,从而强影响模型输出;其次利用这些扰动触发器生成良性对抗扰动,干扰模型对后门触发器的依赖,同时促使模型学习更鲁棒的决策边界;最后引入自适应缩放机制,动态调节扰动强度,在防御强度与模型性能间取得平衡。实验表明,FedBAP在三类后门攻击下分别将攻击成功率降低0.22%-5.34%、0.48%-6.34%和97.22%-97.6%,尤其对新型后门攻击表现优异。
原文摘要 · Abstract (English)
Federated Learning (FL) enables collaborative model training while preserving data privacy, but it is highly vulnerable to backdoor attacks. Most existing defense methods in FL have limited effectiveness due to their neglect of the model's over-reliance on backdoor triggers, particularly as the proportion of malicious clients increases. In this paper, we propose FedBAP, a novel defense framework for mitigating backdoor attacks in FL by reducing the model's reliance on backdoor triggers. Specifically, first, we propose a perturbed trigger generation mechanism that creates perturbation triggers precisely matching backdoor triggers in location and size, ensuring strong influence on model outputs. Second, we utilize these perturbation triggers to generate benign adversarial perturbations that disrupt the model's dependence on backdoor triggers while forcing it to learn more robust decision boundaries. Finally, we design an adaptive scaling mechanism to dynamically adjust perturbation intensity, effectively balancing defense strength and model performance. The experimental results demonstrate that FedBAP reduces the attack success rates by 0.22%-5.34%, 0.48%-6.34%, and 97.22%-97.6% under three types of backdoor attacks, respectively. In particular, FedBAP demonstrates outstanding performance against novel backdoor attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。