发表机构
Indian Institute of Technology, Bombay(印度理工学院孟买分校)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究针对联邦条件GAN,提出并验证了标签翻转及过采样变体攻击,发现其语义损害随中毒强度线性增长、分布偏差二次增长,攻击有效且难检测。
AI 中文摘要
在生成对抗网络(GAN)的联邦学习设置中,存在多种可能的对抗攻击,其中一种是标签翻转攻击:恶意客户端在本地训练期间故意修改标签信息,以操纵全局生成器,其目标是使学习到的生成分布发生偏移,从而让以目标标签为条件的样本被映射到源类别。本研究通过理论分析与实证评估,探究联邦GAN中标签翻转攻击的有效性;还考虑了一种基于过采样的变体攻击,恶意客户端在本地训练期间提升中毒样本的权重,以放大其对聚合后全局模型的影响。我们通过计算干净类别条件分布与中毒类别条件分布之间的Kullback-Leibler散度来量化由此产生的分布偏移,结果显示,在FEMNIST、MNIST和CIFAR10数据集上,无论是理论分析还是实验验证均表明,攻击的语义损害随有效中毒强度线性增长,而与真实目标分布的偏差仅呈二次增长,这使得该攻击既有效又难以通过与标签无关的指标检测到。
英文摘要
In a federated learning setup for GANs, several adversarial attacks are possible. One such attack is label flipping, in which malicious clients deliberately alter label information during local training in order to manipulate the global generator. The objective of this attack is to skew the learned generation distribution so that samples conditioned on a target label are instead mapped to a source class. In this work, we investigate the effectiveness of label flipping attacks in federated GANs through both theoretical analysis and empirical evaluation. We further consider an oversampling based variant, in which malicious clients upweight poisoned samples during local training to amplify their influence on the aggregated global model. We quantify the resulting distributional shift by computing the Kullback Leibler divergence between the clean and poisoned class conditional distributions, and show both analytically and on FEMNIST, MNIST, and CIFAR10 that the semantic damage of the attack grows linearly in the effective poisoning strength while deviation from the true target distribution grows only quadratically, making the attack effective yet difficult to detect from label agnostic metrics.
Comments10 pages, 8 figures, FedKDD/FedMAS 2026 - KDD Workshop