主动检测并防御去中心化联邦学习中的隐蔽后门攻击。
Beyond Passive Aggregation: Active Auditing and Topology-Aware Defense in Decentralized Federated Learning
- 用动态模型分析攻击在复杂网络中的传播规律。
- 通过私有探测器发现传统方法无法识别的隐藏后门。
- 根据网络结构优化防御部署,适合高安全需求场景。
去中心化联邦学习(DFL)极易受到自适应后门攻击,现有被动防御手段难以应对。本文提出一种主动干预的审计框架:首先建立动力学模型,刻画攻击更新在复杂图拓扑中的时空扩散过程;其次引入一系列主动审计指标,包括随机熵异常、随机平滑KL散度和激活峰度,利用私有探测器对本地模型进行压力测试,有效暴露传统静态检测无法发现的潜在后门;此外,设计了拓扑感知的防御部署策略以增强全局聚合的鲁棒性。理论分析证明系统在攻防共演化下的收敛性。多架构的实证评估显示,该框架在抑制隐蔽自适应后门方面优于现有先进防御方法,同时保持主任务性能。
原文摘要 · Abstract (English)
Decentralized Federated Learning (DFL) remains highly vulnerable to adaptive backdoor attacks designed to bypass traditional passive defense metrics. To address this limitation, we shift the defensive paradigm toward a novel active, interventional auditing framework. First, we establish a dynamical model to characterize the spatiotemporal diffusion of adversarial updates across complex graph topologies. Second, we introduce a suite of proactive auditing metrics, stochastic entropy anomaly, randomized smoothing Kullback-Leibler divergence, and activation kurtosis. These metrics utilize private probes to stress-test local models, effectively exposing latent backdoors that remain invisible to conventional static detection. Furthermore, we implement a topology-aware defense placement strategy to maximize global aggregation resilience. We provide theoretical property for the system's convergence under co-evolving attack and defense dynamics. Numeric empirical evaluations across diverse architectures demonstrate that our active framework is highly competitive with state-of-the-art defenses in mitigating stealthy, adaptive backdoors while preserving primary task utility.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。