研究联邦学习中攻击与防御的可迁移性,提升系统安全性。
Rethinking the Transferable Adversarial Attacks and Robust Defense in Federated Learning

- 分析对抗样本在不同客户端间的可迁移性,揭示其与数据分布的关系。
- 提出基于对抗训练的防御机制,有效抵御可迁移攻击。
- 在真实数据集上验证方法,适合关注隐私与安全的研究者。
联邦学习(FL)的发展提升了用户数据隐私保护,并拓展了机器学习的应用场景。然而,大量用户的参与也为各类攻击创造了机会,如投毒攻击、拜占庭攻击和对抗样本攻击。近期研究表明,现有投毒和拜占庭攻击在真实联邦学习场景中难以实现有效渗透,原因在于强假设,如客户端选择率和恶意客户端比例。本文分析了对抗样本在不同客户端模型间的可迁移性,以理解其与客户端数据分布的关系。为缓解可迁移对抗样本的威胁,设计了一种基于模型鲁棒性可迁移性的防御机制,通过对抗训练实现。通过理论分析可迁移性,深入揭示了对抗样本特性及联邦学习系统的脆弱性。所提出的对抗攻击与防御方法在多种真实数据集和设置下进行了评估,性能优于现有最先进方法。
原文摘要 · Abstract (English)
The development of federated learning (FL) techniques has helped improve the privacy preservation of users' data and extended the applications of machine learning models. However, the involvement of a large number of users in FL also creates open opportunities for different adversaries, such as poisoning attacks, Byzantine attacks, and adversarial example attacks. Yet, recent research has disclosed that existing poisoning attacks and Byzantine attacks can not achieve satisfactory penetration in realistic FL scenarios caused by strong assumptions, \textit{e.g.,} client selection rate, and the ratio of malicious attackers. In this paper, the transferability of adversarial examples among different client models is analyzed to understand the relation between adversarial examples and clients' data distribution. Moreover, to mitigate the attacks of transferable adversarial examples, we design a defense mechanism stemming from the transferability of model robustness by adversarial training. As a result, through theoretical analysis of transferability, we gain insights into adversarial examples and the vulnerability of federated learning systems. Our proposed adversarial attack and defense methods are evaluated via real-life datasets in various settings to show their performance over the existing state-of-the-art methods.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。