arXiv:2608.11423cs.LGcs.CR2026-08

对比五种聚合方法在多种攻击下的表现,发现剪裁均值最抗干扰。

Analysis of Federated Aggregation under Model Poisoning and Backdoor Attacks: A Reconstructed Cross-Dataset and Cross-Architecture Benchmark

论文配图:Analysis of Federated Aggregation under Model Poisoning and Backdoor Attacks: A Reconstructed Cross-Dataset and Cross-Architecture Benchmark
图 1 · 摘自论文原文
  • 构建跨数据集与模型的500组实验矩阵,评估不同攻击场景
  • 剪裁均值在干净数据下准确率达76.02%,排名最高
  • 揭示现有指标可能误报,适合安全研究者参考

联邦聚合方法的鲁棒性比较需综合考虑预测性能、威胁定义、指标语义与执行溯源。本文重建了包含五种聚合方法、五种数据集、五种模型架构及四种条件(干净、符号翻转、高斯、BadNets)的500单元实验矩阵。共识别出454次成功执行记录,36次修复或重跑记录,10个清洁SVHN单元仅依赖摘要溯源。剪裁均值在干净条件下取得最高宏平均准确率(76.02%)和最低任务内排名均值(1.70)。Krum在符号翻转与高斯配置下表现最佳。当限制为21个所有方法-条件组合均有原始成功日志的任务对时,相对排名不变。审计发现,所供BadNets指标在目标标签计数前即触发测试输入,实际反映的是触发目标标签率(TTLR),而非常规排除目标的攻击成功率。进一步审计发现FedPARETO框架存在路径漏洞:预测摘要可能描述未污染本地模型,但聚合权重却应用于独立污染的更新,导致报告结果与聚合更新不一致。标准矩阵中每单元仅有一个种子,攻击与配置谱系不完整。因此结论应视为对已记录配置的描述性对比,而非统计估计或通用鲁棒性断言。

原文摘要 · Abstract (English)

Robust comparisons of federated aggregation methods require joint consideration of predictive performance, threat definitions, metric semantics, and execution provenance. A 500-cell seed-1 evaluation matrix was reconstructed across five aggregation methods, five datasets, five architectures, and four recorded conditions: clean, sign-flipping, Gaussian, and BadNets. Successful execution logs were identified for 454 original runs and 36 repaired or rerun executions, whereas 10 clean SVHN cells were supported by summary-only provenance. Trimmed Mean achieved the highest clean macro-mean accuracy (76.02%) and the lowest mean within-task rank (1.70). Krum attained the highest recorded accuracy under both sign-flipping and Gaussian configurations. These relative rankings remained unchanged when analysis was restricted to 21 task pairs for which original successful logs were available for every method-condition combination. Audit of the supplied BadNets metric implementation established that every test input is triggered prior to target-label counting; consequently, the retained metric represents Triggered Target-Label Rate (TTLR) rather than a conventional target-excluding attack success rate. An audit of the supplied FedPARETO scaffold further identified a pathway in which predictive summaries may characterize an uncorrupted local model while the aggregation weight is applied to a separately corrupted update, introducing a potential discrepancy between reported predictive outcomes and the updates used for aggregation. The canonical matrix contains a single identified seed for each cell, and exact attack and configuration lineage is incomplete. Accordingly, the findings should be interpreted as descriptive comparisons within the recorded configurations and not as statistical estimates or universal claims regarding robustness.

联邦学习模型安全对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。