加权平均聚合器在异构去中心化学习中竟比鲁棒聚合器更抗标签投毒攻击。
Topology-Independent Robustness of the Weighted Mean under Label Poisoning Attacks in Heterogeneous Decentralized Learning
- 提出加权平均聚合器在异构场景下具拓扑无关的鲁棒性。
- 当全局污染率低于局部污染率时,加权平均性能优于鲁棒聚合器。
- 适合研究去中心化系统安全、网络拓扑影响的学者参考。
去中心化信号处理与机器学习系统面临恶意攻击时的鲁棒性至关重要。典型攻击如标签投毒:部分节点使用被污染的本地标签训练模型并共享。现有工作多聚焦设计鲁棒聚合器,而加权平均聚合器常被视为简单且脆弱的基线。本文分析了在标签投毒攻击下,去中心化梯度下降中鲁棒聚合器与加权平均聚合器的性能。理论结果表明,鲁棒聚合器的学习误差依赖于网络拓扑,而加权平均聚合器的表现则与拓扑无关。令人惊讶的是,尽管通常被认为脆弱,加权平均聚合器在足够异构的条件下反而能超越鲁棒聚合器,尤其当:(i) 全局污染率(整个网络中被污染节点比例)低于局部污染率(普通节点邻居中最大被污染比例);(ii) 普通节点构成的网络不连通;或 (iii) 普通节点网络稀疏且局部污染率高。实验结果验证了理论发现,凸显了网络拓扑在标签投毒攻击鲁棒性中的关键作用。
原文摘要 · Abstract (English)
Robustness to malicious attacks is crucial for practical decentralized signal processing and machine learning systems. A typical example of such attacks is label poisoning, meaning that some agents possess corrupted local labels and share models trained on these poisoned data. To defend against malicious attacks, existing works often focus on designing robust aggregators; meanwhile, the weighted mean aggregator is typically considered a simple, vulnerable baseline. This paper analyzes the robustness of decentralized gradient descent under label poisoning attacks, considering both robust and weighted mean aggregators. Theoretical results reveal that the learning errors of robust aggregators depend on the network topology, whereas the performance of weighted mean aggregator is topology-independent. Remarkably, the weighted mean aggregator, although often considered vulnerable, can outperform robust aggregators under sufficient heterogeneity, particularly when: (i) the global contamination rate (i.e., the fraction of poisoned agents for the entire network) is smaller than the local contamination rate (i.e., the maximal fraction of poisoned neighbors for the regular agents); (ii) the network of regular agents is disconnected; or (iii) the network of regular agents is sparse and the local contamination rate is high. Empirical results support our theoretical findings, highlighting the important role of network topology in the robustness to label poisoning attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。