恶意客户端通过提升公平性损失,隐蔽地加剧联邦学习中的偏见。
Fairness-Constrained Optimization Attack in Federated Learning
- 设计攻击使客户端在训练时主动增加公平性损失
- 仅一个恶意客户端即可将偏见提升至90%
- 攻击隐匿性强,不降低全局准确率,适合研究安全与公平的学者
联邦学习(FL)是一种保护隐私的协作机器学习技术,支持跨群体参与者共同训练模型而不共享数据。由于各参与方独立处理本地数据,系统易受投毒攻击。同时,不同数据分布或历史偏见会随协作传播,造成无意偏见。本文提出一种故意的公平性攻击:客户端在训练中主动增大公平性损失,即使在同质数据分布下也如此,通过求解公平性度量(如人口均等性和等机会)的优化问题实现。该攻击隐蔽且难以检测,因全局准确率未下降。我们在多种数据集和设置下测试该攻击,评估其对当前最先进的拜占庭鲁棒及公平感知聚合方法的影响。实验证明,仅一个恶意客户端即可使偏见增加高达90%。
原文摘要 · Abstract (English)
Federated learning (FL) is a privacy-preserving machine learning technique that facilitates collaboration among participants across demographics. FL enables model sharing, while restricting the movement of data. Since FL provides participants with independence over their training data, it becomes susceptible to poisoning attacks. Such collaboration also propagates bias among the participants, even unintentionally, due to different data distribution or historical bias present in the data. This paper proposes an intentional fairness attack, where a client maliciously sends a biased model, by increasing the fairness loss while training, even considering homogeneous data distribution. The fairness loss is calculated by solving an optimization problem for fairness metrics such as demographic parity and equalized odds. The attack is insidious and hard to detect, as it maintains global accuracy even after increasing the bias. We evaluate our attack against the state-of-the-art Byzantine-robust and fairness-aware aggregation schemes over different datasets, in various settings. The empirical results demonstrate the attack efficacy by increasing the bias up to 90\%, even in the presence of a single malicious client in the FL system.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。