攻击者优化恶意更新,骗过联邦学习的鲁棒聚合机制。
Bypassing Krum: Selection-Aware Backdoor Attacks in Federated Learning

- 设计双阶段优化,让恶意更新既像正常更新又在聚合时占优。
- 在标准数据集上攻击成功率更高,且不影响正常模型准确率。
- 适合研究联邦学习安全的开发者,揭示距离聚合的潜在漏洞。
鲁棒聚合方法广泛用于联邦学习以缓解恶意客户端的影响。基于距离的聚合规则(如 Krum、Multi-Krum)假设良性更新会形成紧凑簇,因此选择与多数更新相近的更新。然而,这些方法依赖的几何特性可被自适应攻击者利用。本文提出 Krum-Proxy 攻击,一种选择感知的后门注入策略,能持续绕过拜占庭鲁棒聚合。该方法不依赖简单的缩放或约束,而是主动优化恶意更新,使其渗入良性分布的密集核心。通过两阶段优化:分离任务相关攻击目标与几何感知精修,结合最近邻代理、随机参考建模和锚点引导对齐,使恶意更新在更新空间中占据聚合偏好区域。为保持隐蔽性,引入投影机制,将恶意更新限制在合理的范数与方差范围内。在标准联邦学习基准测试中,Krum-Proxy 在保持干净准确率的同时实现更高攻击成功率,凸显基于距离的聚合对选择感知攻击的脆弱性。
原文摘要 · Abstract (English)
Robust aggregation methods are widely used in federated learning to mitigate the impact of adversarial client behavior. Distance-based aggregation rules, such as Krum and Multi-Krum, select updates that are closest to the majority under the assumption that benign updates form a compact cluster. However, these methods rely on geometric properties that can be exploited by adaptive adversaries. We introduce the Krum-Proxy attack, a selection-aware backdoor injection strategy that consistently bypasses Byzantine-robust aggregation. Rather than relying on naive scaling or constraining, our method actively optimizes malicious updates to infiltrate the dense core of the benign distribution. The proposed method constructs adversarial updates that are not only similar to benign updates but are also optimized to lie in regions of the update space that are favored during aggregation. This is achieved through a two-stage optimization procedure that separates task-specific attack objectives from geometry-aware refinement, using a nearest-neighbor proxy, stochastic reference modeling, and anchor-guided alignment. To maintain stealth, we introduce a projection mechanism that constrains adversarial updates within realistic norm and variance bounds. Experiments on standard federated learning benchmarks show that Krum-Proxy achieves higher attack success while preserving clean accuracy, highlighting the vulnerability of distance-based aggregation to selection-aware adversaries.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。