发表机构
Shandong Computer Science Center; Qilu University of Technology (Shandong Academy of Sciences); College of computer science and technology, China University of Petroleum; School of Computer Science and Engineering, University of Electronic Science and Technology of China; Big Data Institute, Qilu University of Technology(山东计算机科学中心; 齐鲁工业大学(山东省科学院); 中国石油大学计算机科学与技术学院; 电子科技大学计算机科学与工程学院; 齐鲁工业大学大数据研究院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对联邦学习易受后门攻击的问题,提出FedDAB两阶段防御方法,结合本地对比正则化与对齐检测,经理论证明和实验验证,其防御效果优于现有方法。
AI 中文摘要
联邦学习(FL)因边缘计算场景下的分布式特性易受后门攻击。现有防御方法效果有限,原因在于其忽略了统计异质性导致的良性本地更新偏差,以及后门攻击的隐蔽性。为解决这些问题,我们提出FedDAB,这是一种结合本地对比正则化与对齐检测的两阶段防御方法。第一阶段,FedDAB在本地目标中引入新型模型对比项,以增强良性更新间的方向与幅度一致性;第二阶段,FedDAB采用对齐检测策略,从整体方向对齐和参数级对齐两方面评估各本地更新与历史信息的匹配度,将对齐模式异常的更新排除在全局聚合之外。我们从理论上证明了FedDAB的鲁棒性,其收敛速率为$\boldsymbol{\textit{O}}(1/T)$。大量实验表明,FedDAB在防御后门攻击方面的性能优于现有防御方法。
英文摘要
Federated Learning (FL) is vulnerable to backdoor attacks because of its distributed nature in edge computing scenarios. Existing defense methods show limited efficacy as they overlook the deviations among benign local updates caused by statistical heterogeneity and the stealthiness of backdoor attacks. To tackle these issues, we propose FedDAB, a two-phase method that combines local contrastive regularization with alignment checking, to defend against backdoor attacks. In the first phase, FedDAB introduces a novel model-contrastive term into the local objective to enhance direction and magnitude consistency among benign updates. In the second phase, FedDAB employs an alignment checking strategy to evaluate each local update in terms of overall-direction alignment and parameter-level alignment with historical information, excluding updates that exhibit abnormal alignment patterns from global aggregation. We theoretically prove FedDAB's robustness with a convergence rate of $\mathcal{O}(1/T)$. Extensive experiments show that FedDAB outperforms existing defense methods against backdoor attacks.