CACTUS:去中心化联邦学习中掩码引导的语义干净标签后门
CACTUS: Mask-Guided Semantic Clean-Label Backdoors in Decentralized Federated Learning
浏览论文内容
中文总结 AI 辅助
CACTUS针对去中心化联邦学习的后门植入问题,通过掩码引导的语义操作实现了高攻击成功率,可在多模态任务中通过联邦聚合传播后门。
中文摘要 AI 辅助
联邦学习(FL)中的语义触发器比合成补丁更不易被察觉,但依赖样本的放置方式可能会削弱聚合轮次中的后门植入效果,在去中心化联邦学习(DFL)中这一挑战更为复杂,因为依赖拓扑的对等聚合会反复混合本地模型。CACTUS将标签一致的语义对转换为目标导向的表征偏移;掩码引导的模态特定算子隔离触发器效果,在对等聚合前将这些效果跨样本耦合,并反事实应用于干净的非目标嵌入。实验涵盖语音、文本、表格和图像任务,涉及9种聚合规则;在30%恶意节点的情况下,CACTUS在Speech Commands上达到9种规则的平均攻击成功率(ASR)为51.2%,且在4种模态中的3种上达到评估攻击中最高的9种规则平均ASR。敏感性分析显示,ASR随网络拓扑变化,且随恶意节点比例增加而升高。这些结果表明,CACTUS可通过重复的DFL聚合传播后门。
英文摘要
Semantic triggers in federated learning (FL) can be less conspicuous than synthetic patches, but sample-dependent placement may weaken backdoor implantation across aggregation rounds. This challenge is compounded in decentralized FL (DFL), where topology-dependent peer aggregation repeatedly mixes local models. CACTUS converts label-consistent semantic pairs into target-directed representation shifts. Mask-guided, modality-specific operators isolate trigger effects, couple them across samples, and apply the shifts counterfactually to clean non-target embeddings before peer aggregation. Experiments cover speech, text, tabular, and image tasks under nine aggregation rules. With 30\% malicious nodes, CACTUS reaches a nine-rule mean attack success rate (ASR) of 51.2\% on Speech Commands and the highest nine-rule mean ASR among evaluated attacks on three of four modalities. Sensitivity analyses show that ASR varies with network topology and increases with the malicious-node ratio. These results indicate that CACTUS can propagate backdoors through repeated DFL aggregation.
发表机构
- University of Zurich(苏黎世大学)
机构由 AI 辅助整理,请以论文原文为准。