arXiv:2509.00540cs.LGcs.CR2025-09

攻击者通过伪造更新,在破坏全局模型的同时提升自己私有模型性能。

FedThief: Harming Others to Benefit Oneself in Self-Centered Federated Learning

  • 攻击者上传篡改的模型更新,同时利用差异感知集成技术融合全局与本地知识。
  • 实验显示攻击使全局模型性能下降,而攻击者私有模型显著优于全局模型。
  • 适合关注自利性攻击防御的系统设计者与安全研究人员参考。

在联邦学习中,参与者上传的模型更新无法直接验证,系统易受恶意攻击。现有攻击策略使攻击者上传被篡改的模型更新以降低全局模型性能,但攻击者自身私有模型也会受损,无实际收益。现实中攻击者具有自利动机:目标是通过构建比其他参与者更优的模型获得竞争优势,而非单纯制造破坏。本文研究一种新型自利型联邦学习(SCFL)攻击范式,攻击者不仅通过攻击降低全局模型性能,还在联邦学习过程中提升自身私有模型。我们提出名为FedThief的框架,通过在上传阶段注入修改内容来降低全局模型性能;同时,利用差异感知集成技术增强私有模型性能,其中“差异”量化了私有模型与全局模型之间的偏离程度,从而融合全局更新与本地知识。大量实验表明,该方法有效降低全局模型性能,同时使攻击者获得显著优于全局模型的集成模型。

原文摘要 · Abstract (English)

In federated learning, participants' uploaded model updates cannot be directly verified, leaving the system vulnerable to malicious attacks. Existing attack strategies have adversaries upload tampered model updates to degrade the global model's performance. However, attackers also degrade their own private models, gaining no advantage. In real-world scenarios, attackers are driven by self-centered motives: their goal is to gain a competitive advantage by developing a model that outperforms those of other participants, not merely to cause disruption. In this paper, we study a novel Self-Centered Federated Learning (SCFL) attack paradigm, in which attackers not only degrade the performance of the global model through attacks but also enhance their own models within the federated learning process. We propose a framework named FedThief, which degrades the performance of the global model by uploading modified content during the upload stage. At the same time, it enhances the private model's performance through divergence-aware ensemble techniques, where "divergence" quantifies the deviation between private and global models, that integrate global updates and local knowledge. Extensive experiments show that our method effectively degrades the global model performance while allowing the attacker to obtain an ensemble model that significantly outperforms the global model.

联邦学习自利攻击模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。