arXiv:2608.09314cs.LG2026-08

恶意客户端通过篡改标签和数据加权,让联邦生成模型错误生成指定类别的图像。

Targeted Label-Flipping and Oversampling Attacks on Federated Conditional GANs

论文配图:Targeted Label-Flipping and Oversampling Attacks on Federated Conditional GANs
图 1 · 摘自论文原文
  • 设计标签翻转与数据过采样结合的攻击,操控联邦生成模型输出。
  • 在FEMNIST、MNIST、CIFAR10上验证攻击使生成分布偏移,且越难被检测。
  • 攻击效果随毒化强度线性增长,但偏差呈二次增长,隐蔽性强。

在联邦学习环境下的生成对抗网络中,存在多种攻击方式。其中标签翻转攻击指恶意客户端在本地训练时故意修改标签信息,以操纵全局生成器。攻击目标是使针对目标标签的条件生成样本被映射到源类别。本文通过理论分析与实证评估,研究此类攻击在联邦生成模型中的有效性。进一步提出一种基于过采样的变体攻击,即恶意客户端在本地训练中对污染样本进行加权,以放大其对全局模型的影响。我们通过计算干净与污染类别条件分布间的KL散度来量化分布偏移,在FEMNIST、MNIST和CIFAR10上均发现:攻击导致的语义破坏程度随有效毒化强度线性增长,而偏离真实目标分布的程度仅呈二次增长,使得攻击既有效又难以通过标签无关指标检测。

原文摘要 · Abstract (English)

In a federated learning setup for GANs, several adversarial attacks are possible. One such attack is label flipping, in which malicious clients deliberately alter label information during local training in order to manipulate the global generator. The objective of this attack is to skew the learned generation distribution so that samples conditioned on a target label are instead mapped to a source class. In this work, we investigate the effectiveness of label flipping attacks in federated GANs through both theoretical analysis and empirical evaluation. We further consider an oversampling based variant, in which malicious clients upweight poisoned samples during local training to amplify their influence on the aggregated global model. We quantify the resulting distributional shift by computing the Kullback Leibler divergence between the clean and poisoned class conditional distributions, and show both analytically and on FEMNIST, MNIST, and CIFAR10 that the semantic damage of the attack grows linearly in the effective poisoning strength while deviation from the true target distribution grows only quadratically, making the attack effective yet difficult to detect from label agnostic metrics.

联邦学习生成模型安全攻击数据投毒

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。