提出DEFEND机制,精准识别并剔除联邦学习中的恶意客户端。
DEFEND: Poisoned Model Detection and Malicious Client Exclusion Mechanism for Secure Federated Learning-based Road Condition Classification
- 通过神经元幅度分析与高斯混合模型检测被污染模型
- 在攻击下仍保持与无攻击时相当的模型性能
- 适合需要高安全性的智能交通道路状况分类系统
联邦学习(FL)受到智能交通系统(ITS)领域的关注,可实现隐私保护下的协同训练,尤其适用于基于摄像头的道路状况分类(RCC)。然而,开放协作也使系统面临威胁,如发动定向标签翻转攻击(TLFA)的不良参与者,其通过污染数据误导模型预测,将真实路况(如湿滑路面)误判为错误目标(如干燥路面),危及交通安全。现有防御方法因缺乏针对TLFA的特定模型异常检测,且未在检测后排除恶意客户端,难以在攻击下维持接近无攻击时的性能。为此,本文提出DEFEND机制,利用神经元级幅度分析识别攻击目标,并结合高斯混合模型(GMM)聚类进行模型污染检测。该机制在每轮中剔除受污染模型贡献,并动态调整客户端评分,最终排除恶意客户端。大量实验表明,DEFEND能有效抵御TLFA,在多种联邦学习-RCC模型与任务中表现优于7种基线方法,性能提升至少15.78%,并在攻击下实现与无攻击场景同等的模型精度。
原文摘要 · Abstract (English)
Federated Learning (FL) has drawn the attention of the Intelligent Transportation Systems (ITS) community. FL can train various models for ITS tasks, notably camera-based Road Condition Classification (RCC), in a privacy-preserving collaborative way. However, opening up to collaboration also opens FL-based RCC systems to adversaries, i.e., misbehaving participants that can launch Targeted Label-Flipping Attacks (TLFAs) and threaten transportation safety. Adversaries mounting TLFAs poison training data to misguide model predictions, from an actual source class (e.g., wet road) to a wrongly perceived target class (e.g., dry road). Existing countermeasures against poisoning attacks cannot maintain model performance under TLFAs close to the performance level in attack-free scenarios, because they lack specific model misbehavior detection for TLFAs and neglect client exclusion after the detection. To close this research gap, we propose DEFEND, which includes a poisoned model detection strategy that leverages neuron-wise magnitude analysis for attack goal identification and Gaussian Mixture Model (GMM)-based clustering. DEFEND discards poisoned model contributions in each round and adapts accordingly client ratings, eventually excluding malicious clients. Extensive evaluation involving various FL-RCC models and tasks shows that DEFEND can thwart TLFAs and outperform seven baseline countermeasures, with at least 15.78% improvement, with DEFEND remarkably achieving under attack the same performance as in attack-free scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。