模型投毒与后门攻击下联邦聚合的分析:重构跨数据集与跨架构基准
Analysis of Federated Aggregation under Model Poisoning and Backdoor Attacks: A Reconstructed Cross-Dataset and Cross-Architecture Benchmark
浏览论文内容
中文总结 AI 辅助
本文重构跨数据集与跨架构基准,分析模型投毒与后门攻击下联邦聚合的性能,发现Trimmed Mean干净准确率最高、Krum在特定攻击下准确率最高,还指出BadNets指标及FedPARETO框架的潜在问题。
中文摘要 AI 辅助
联邦聚合方法的鲁棒性比较需综合考虑预测性能、威胁定义、指标语义及执行溯源。本文重构了一个含500个单元的seed-1评估矩阵,涵盖5种聚合方法、5个数据集、5种架构及4种记录条件:干净、符号翻转、高斯及BadNets。在原始运行中,454次成功执行日志、36次修复或重运行执行被识别,而10个干净SVHN单元仅由仅摘要溯源支持。Trimmed Mean在干净条件下的宏观平均准确率最高(76.02%),任务内平均排名最低(1.70);Krum在符号翻转和高斯配置下均达到最高记录准确率。当分析限制为每种方法-条件组合均有原始成功日志的21个任务对时,这些相对排名保持不变。对所提供的BadNets指标实现的审计显示,每个测试输入在目标标签计数前被触发,因此保留的指标代表触发目标标签率(TTLR),而非传统的排除目标的攻击成功率。对所提供的FedPARETO框架的进一步审计发现,存在一种可能的路径:预测摘要可表征未损坏的本地模型,而聚合权重应用于单独损坏的更新,导致报告的预测结果与聚合所用更新之间存在潜在差异。规范矩阵的每个单元包含一个已识别的seed,且确切的攻击和配置谱系不完整,因此,研究结果应被解释为记录配置内的描述性比较,而非关于鲁棒性的统计估计或普遍主张。
英文摘要
Robust comparisons of federated aggregation methods require joint consideration of predictive performance, threat definitions, metric semantics, and execution provenance. A 500-cell seed-1 evaluation matrix was reconstructed across five aggregation methods, five datasets, five architectures, and four recorded conditions: clean, sign-flipping, Gaussian, and BadNets. Successful execution logs were identified for 454 original runs and 36 repaired or rerun executions, whereas 10 clean SVHN cells were supported by summary-only provenance. Trimmed Mean achieved the highest clean macro-mean accuracy (76.02%) and the lowest mean within-task rank (1.70). Krum attained the highest recorded accuracy under both sign-flipping and Gaussian configurations. These relative rankings remained unchanged when analysis was restricted to 21 task pairs for which original successful logs were available for every method-condition combination. Audit of the supplied BadNets metric implementation established that every test input is triggered prior to target-label counting; consequently, the retained metric represents Triggered Target-Label Rate (TTLR) rather than a conventional target-excluding attack success rate. An audit of the supplied FedPARETO scaffold further identified a pathway in which predictive summaries may characterize an uncorrupted local model while the aggregation weight is applied to a separately corrupted update, introducing a potential discrepancy between reported predictive outcomes and the updates used for aggregation. The canonical matrix contains a single identified seed for each cell, and exact attack and configuration lineage is incomplete. Accordingly, the findings should be interpreted as descriptive comparisons within the recorded configurations and not as statistical estimates or universal claims regarding robustness.
发表机构
- Gargi Memorial Institute of Technology(加尔吉纪念技术学院)
- Maulana Abul Kalam Azad University of Technology(毛拉纳·阿卜尔·卡拉姆·阿扎德技术大学)
- Variable Energy Cyclotron Centre(可变能量回旋加速器中心)
- Homi Bhabha National Institute(霍米·巴巴国家学院)
机构由 AI 辅助整理,请以论文原文为准。