arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.06637cs.LGcs.AI

绕过Krum:联邦学习中的感知选择后门攻击

Bypassing Krum: Selection-Aware Backdoor Attacks in Federated Learning

Srinivasan Subramanian, Md. Abdullah Al Hafiz Khan, Kazi Aminul Islam

AI总结:

本文提出Krum-Proxy攻击,通过两阶段优化等技术绕过联邦学习的Krum等基于距离的鲁棒聚合,在保持干净准确率的同时提升了攻击成功率,暴露了此类聚合方法的脆弱性。

AI中文摘要:

联邦学习中广泛使用鲁棒聚合方法来减轻恶意客户端行为的影响,基于距离的聚合规则(如Krum和Multi-Krum)假设良性更新形成紧凑集群,选择与多数最接近的更新。但这些方法依赖的几何属性可被自适应攻击者利用。本文提出Krum-Proxy攻击,一种感知选择的后门注入策略,可始终绕过拜占庭鲁棒聚合。该方法不依赖简单缩放或约束,而是主动优化恶意更新以渗透到良性分布的密集核心,构建的对抗更新不仅与良性更新相似,还被优化至聚合时偏好的更新空间区域,通过两阶段优化实现:将特定任务攻击目标与几何感知细化分离,使用最近邻代理、随机参考建模和锚点引导对齐;为保持隐蔽性,引入投影机制将对抗更新约束在合理的范数和方差范围内。在标准联邦学习基准上的实验表明,Krum-Proxy在保持干净准确率的同时实现了更高的攻击成功率,凸显了基于距离的聚合对感知选择型攻击者的脆弱性。

英文摘要:

Robust aggregation methods are widely used in federated learning to mitigate the impact of adversarial client behavior. Distance-based aggregation rules, such as Krum and Multi-Krum, select updates that are closest to the majority under the assumption that benign updates form a compact cluster. However, these methods rely on geometric properties that can be exploited by adaptive adversaries. We introduce the Krum-Proxy attack, a selection-aware backdoor injection strategy that consistently bypasses Byzantine-robust aggregation. Rather than relying on naive scaling or constraining, our method actively optimizes malicious updates to infiltrate the dense core of the benign distribution. The proposed method constructs adversarial updates that are not only similar to benign updates but are also optimized to lie in regions of the update space that are favored during aggregation. This is achieved through a two-stage optimization procedure that separates task-specific attack objectives from geometry-aware refinement, using a nearest-neighbor proxy, stochastic reference modeling, and anchor-guided alignment. To maintain stealth, we introduce a projection mechanism that constrains adversarial updates within realistic norm and variance bounds. Experiments on standard federated learning benchmarks show that Krum-Proxy achieves higher attack success while preserving clean accuracy, highlighting the vulnerability of distance-based aggregation to selection-aware adversaries.

补充信息

↑