arXiv:2510.15109cs.NIcs.AI2025-10被引 1

针对车载网络中的分布式联邦学习,设计针对性攻击并提出有效防御方案。

Targeted Attacks and Defenses for Distributed Federated Learning in Vehicular Networks

  • 通过无中心节点的分布式联邦学习提升系统鲁棒性与可扩展性。
  • 验证了分布式学习在抵御数据投毒和后门攻击上优于单机学习。
  • 为车联网场景提供实用的对抗性攻击防御机制,适合安全敏感应用。

在新兴网络系统中,车载设备与无人机群等移动边缘设备需在远程、动态且基础设施受限的环境中,利用有限的算力与带宽完成威胁检测等机器学习决策。联邦学习(FL)通过共享本地模型权重而非原始数据,缓解了资源约束与隐私问题,提升了决策可靠性。然而传统FL依赖中心服务器协调每轮模型更新,带来巨大计算负担,且在连接不稳定时不可行。分布式联邦学习(DFL)通过去除中心节点,实现更好的可扩展性、容错能力、学习鲁棒性及更优的防御策略。尽管如此,DFL仍面临日益复杂隐蔽的网络攻击威胁。本文设计了针对训练数据的定向投毒攻击与后门(木马)攻击,揭示车载网络中的新型脆弱性;分析了DFL相较单机学习在抗攻击上的优势,并提出有效的防御机制以增强对新型网络威胁的防护能力。

原文摘要 · Abstract (English)

In emerging networked systems, mobile edge devices such as ground vehicles and unmanned aerial system (UAS) swarms collectively aggregate vast amounts of data to make machine learning decisions such as threat detection in remote, dynamic, and infrastructure-constrained environments where power and bandwidth are scarce. Federated learning (FL) addresses these constraints and privacy concerns by enabling nodes to share local model weights for deep neural networks instead of raw data, facilitating more reliable decision-making than individual learning. However, conventional FL relies on a central server to coordinate model updates in each learning round, which imposes significant computational burdens on the central node and may not be feasible due to the connectivity constraints. By eliminating dependence on a central server, distributed federated learning (DFL) offers scalability, resilience to node failures, learning robustness, and more effective defense strategies. Despite these advantages, DFL remains vulnerable to increasingly advanced and stealthy cyberattacks. In this paper, we design sophisticated targeted training data poisoning and backdoor (Trojan) attacks, and characterize the emerging vulnerabilities in a vehicular network. We analyze how DFL provides resilience against such attacks compared to individual learning and present effective defense mechanisms to further strengthen DFL against the emerging cyber threats.

联邦学习车载网络安全防御对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。