arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

重新思考联邦学习中的可迁移对抗攻击与鲁棒防御

Rethinking the Transferable Adversarial Attacks and Robust Defense in Federated Learning

Zuobin Xiong, Deval Mukherjee, Homook Cho, Wei Li

arXiv 2608.25133首次发表:更新:

发表机构

University of Nevada Las Vegas; Cyber Security Research Center at KAIST; Georgia State University(内华达大学拉斯维加斯分校; 韩国科学技术院网络安全研究中心; 佐治亚州立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文针对联邦学习场景,分析对抗样本的可迁移性,设计基于对抗训练的防御机制,经真实数据集验证其性能优于现有最先进方法。

AI 中文摘要

联邦学习(FL)技术的发展有助于提升用户数据的隐私保护水平,并拓展了机器学习模型的应用场景。然而,大量用户参与联邦学习也为各类攻击者创造了可乘之机,例如投毒攻击、拜占庭攻击和对抗样本攻击。但近期研究表明,由于客户端选择率、恶意攻击者比例等强假设的存在,现有投毒攻击和拜占庭攻击在现实联邦学习场景中无法达到令人满意的渗透效果。本文分析了不同客户端模型间对抗样本的可迁移性,以明确对抗样本与客户端数据分布之间的关联。此外,为缓解可迁移对抗样本的攻击,我们基于对抗训练带来的模型鲁棒性可迁移性设计了一种防御机制。通过对可迁移性的理论分析,我们获得了关于对抗样本和联邦学习系统漏洞的深刻见解。我们提出的对抗攻击与防御方法在多种设置下通过真实数据集进行评估,以展示其相较于现有最先进方法的性能。

英文摘要

The development of federated learning (FL) techniques has helped improve the privacy preservation of users' data and extended the applications of machine learning models. However, the involvement of a large number of users in FL also creates open opportunities for different adversaries, such as poisoning attacks, Byzantine attacks, and adversarial example attacks. Yet, recent research has disclosed that existing poisoning attacks and Byzantine attacks can not achieve satisfactory penetration in realistic FL scenarios caused by strong assumptions, \textit{e.g.,} client selection rate, and the ratio of malicious attackers. In this paper, the transferability of adversarial examples among different client models is analyzed to understand the relation between adversarial examples and clients' data distribution. Moreover, to mitigate the attacks of transferable adversarial examples, we design a defense mechanism stemming from the transferability of model robustness by adversarial training. As a result, through theoretical analysis of transferability, we gain insights into adversarial examples and the vulnerability of federated learning systems. Our proposed adversarial attack and defense methods are evaluated via real-life datasets in various settings to show their performance over the existing state-of-the-art methods.

CommentsAccepted in the ICCCN 2026 conference

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑