提出新型联邦学习投毒攻击,隐蔽性强且不影响主任务精度
PoiCGAN: A Targeted Poisoning Based on Feature-Label Joint Perturbation in Federated Learning
- 通过特征-标签联合扰动,在CGAN中设计隐蔽投毒生成器
- 攻击成功率比基线高83.97%,主任务准确率下降不足8.87%
- 适合研究防御机制或评估系统鲁棒性的研究人员
联邦学习(FL)作为分布式学习范式,在提升计算效率与保护数据隐私方面表现优异,广泛应用于工业图像分类。然而,由于其分布式特性,易受恶意客户端威胁,其中投毒攻击是常见风险。现有方法难以绕过基于模型异常检测的防御机制,常导致中毒模型被识别并移除,削弱其实用性。为兼顾工业图像分类性能与攻击效果,本文提出一种基于特征-标签联合扰动的靶向投毒攻击方法PoiCGAN。该方法通过修改条件生成对抗网络(CGAN)中生成器与判别器的输入,影响训练过程,生成理想的毒化生成器。该生成器不仅能生成特定中毒样本,还能自动完成标签翻转。在多个数据集上的实验表明,本方法攻击成功率较基线高出83.97%,主任务准确率仅下降小于8.87%。此外,中毒样本与恶意模型具有高度隐蔽性。
原文摘要 · Abstract (English)
Federated Learning (FL), as a popular distributed learning paradigm, has shown outstanding performance in improving computational efficiency and protecting data privacy, and is widely applied in industrial image classification. However, due to its distributed nature, FL is vulnerable to threats from malicious clients, with poisoning attacks being a common threat. A major limitation of existing poisoning attack methods is their difficulty in bypassing model performance tests and defense mechanisms based on model anomaly detection. This often results in the detection and removal of poisoned models, which undermines their practical utility. To ensure both the performance of industrial image classification and attacks, we propose a targeted poisoning attack, PoiCGAN, based on feature-label collaborative perturbation. Our method modifies the inputs of the discriminator and generator in the Conditional Generative Adversarial Network (CGAN) to influence the training process, generating an ideal poison generator. This generator not only produces specific poisoned samples but also automatically performs label flipping. Experiments across various datasets show that our method achieves an attack success rate 83.97% higher than baseline methods, with a less than 8.87% reduction in the main task's accuracy. Moreover, the poisoned samples and malicious models exhibit high stealthiness.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。