无需协作的攻击者也能破坏联邦学习,且能绕过主流防御。
XFED: Non-Collusive Model Poisoning Attack Against Byzantine-Robust Federated Classifiers
- 攻击者独立生成恶意更新,不需通信或共享模型。
- 在六大数据集上成功绕过八种前沿防御,优于六种现有攻击。
- 揭示联邦学习安全短板,适合关注隐私与系统安全的研究者。
模型投毒攻击对联邦学习(FL)构成重大安全威胁。现有多数攻击依赖协同,要求恶意客户端交换本地良性模型并同步生成污染更新,但在真实部署中难以维持,因需类似僵尸网络的设备控制,成本高且易被检测。这引出关键问题:攻击是否可在无任何通信的情况下依然有效?为此,我们提出并形式化了「非协同攻击模型」,即所有受损客户端共享相同恶意目标但独立运作。在此模型下,每个攻击者生成恶意更新时无需与其他攻击者通信、访问其更新,也不依赖服务器端防御知识。为验证该威胁模型可行性,我们提出首个聚合无关的非协同投毒攻击——XFED。在六个基准数据集上的实证评估显示,XFED可绕过八种先进防御机制,性能超越六种现有攻击。结果表明,联邦学习系统的安全性远低于预期,亟需更鲁棒且实用的防御方案。
原文摘要 · Abstract (English)
Model poisoning attacks pose a significant security threat to Federated Learning (FL). Most existing model poisoning attacks rely on collusion, requiring adversarial clients to coordinate by exchanging local benign models and synchronizing the generation of their poisoned updates. However, sustaining such coordination is increasingly impractical in real-world FL deployments, as it effectively requires botnet-like control over many devices. This approach is costly to maintain and highly vulnerable to detection. This context raises a fundamental question: Can model poisoning attacks remain effective without any communication between attackers? To address this challenge, we introduce and formalize the \textbf{non-collusive attack model}, in which all compromised clients share a common adversarial objective but operate independently. Under this model, each attacker generates its malicious update without communicating with other adversaries, accessing other clients' updates, or relying on any knowledge of server-side defenses. To demonstrate the feasibility of this threat model, we propose \textbf{XFED}, the first aggregation-agnostic, non-collusive model poisoning attack. Our empirical evaluation across six benchmark datasets shows that XFED bypasses eight state-of-the-art defenses and outperforms six existing model poisoning attacks. These findings indicate that FL systems are substantially less secure than previously believed and underscore the urgent need for more robust and practical defense mechanisms.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。