提出一种隐蔽高效的联邦图学习攻击方法,可绕过主流防御并大幅降低计算开销。
Hide and Find: A Distributed Adversarial Attack on Federated Graph Learning
- 分两阶段攻击:先隐藏扰动器,再利用全局模型高效生成对抗样本
- 在6个大规模数据集上攻击成功率最高,且比现有方法快90%以上
- 能有效绕过3种主流鲁棒防御,适合研究安全与对抗攻击的学者
联邦图学习(FedGL)易受恶意攻击,但设计真正有效且隐蔽的攻击方法仍是重大挑战。现有方法存在成功率低、计算成本高,且易被防御算法识别和抑制的问题。为此,本文提出新型两阶段「隐藏与寻找」分布式对抗攻击方法 FedShift。第一阶段,在 FedGL 开始前,将可学习且隐蔽的“扰动器”注入部分训练数据,微妙地将中毒图表示推向目标类决策边界但不越界,确保训练过程中的隐蔽性;第二阶段,在 FedGL 完成后,利用全局模型信息,以隐藏扰动器作为优化起点,高效搜索对抗扰动。最终,聚合多个恶意客户端的扰动形成有效对抗样本并触发攻击。在六个大规模数据集上的实验表明,本方法攻击效果优于现有先进攻击方法。特别地,其可有效规避三种主流鲁棒联邦学习防御算法,且收敛时间减少超过90%,凸显其卓越的隐蔽性、鲁棒性与效率。
原文摘要 · Abstract (English)
Federated Graph Learning (FedGL) is vulnerable to malicious attacks, yet developing a truly effective and stealthy attack method remains a significant challenge. Existing attack methods suffer from low attack success rates, high computational costs, and are easily identified and smoothed by defense algorithms. To address these challenges, we propose \textbf{FedShift}, a novel two-stage "Hide and Find" distributed adversarial attack. In the first stage, before FedGL begins, we inject a learnable and hidden "shifter" into part of the training data, which subtly pushes poisoned graph representations toward a target class's decision boundary without crossing it, ensuring attack stealthiness during training. In the second stage, after FedGL is complete, we leverage the global model information and use the hidden shifter as an optimization starting point to efficiently find the adversarial perturbations. During the final attack, we aggregate these perturbations from multiple malicious clients to form the final effective adversarial sample and trigger the attack. Extensive experiments on six large-scale datasets demonstrate that our method achieves the highest attack effectiveness compared to existing advanced attack methods. In particular, our attack can effectively evade 3 mainstream robust federated learning defense algorithms and converges with a time cost reduction of over 90\%, highlighting its exceptional stealthiness, robustness, and efficiency.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。