arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.07147cs.LG

联邦学习中的细粒度分布式后门攻击

Fine-grained Distributed Backdoor Attacks in Federated Learning

Jian Wang, Hong Shen, Wei Ke, Xue Hua Liu

首次发表
浏览论文内容

中文总结 AI 辅助

针对联邦学习中的分布式后门攻击,提出细粒度框架FDBA,利用动态触发器和嵌入向量对比学习,以更少中毒样本提升攻击成功率并绕过防御。

中文摘要 AI 辅助

联邦学习作为一种保护隐私的分布式机器学习范式,面临着来自后门攻击的重大威胁。与集中式攻击相比,分布式后门攻击更具危害性,但需要更多中毒样本来弥补因分解而导致的触发器强度损失。固定的触发器模式也容易被鲁棒聚合算法检测到,增加了攻击暴露的风险。为应对这些挑战,我们提出了一种细粒度分布式后门攻击框架(FDBA)。该框架利用动态触发器生成和嵌入向量优化,以更少的中毒样本执行攻击。首先,我们设计了一种基于图像边缘结构的动态触发器生成方法,使用Canny算法提取边缘特征,然后注入拉普拉斯噪声。应用RGB通道分解以实现分布式触发器的隐蔽适配,降低被检测的概率。其次,我们引入了一种嵌入向量对比学习策略,迫使中毒样本在特征空间中接近目标类中心,从而增强攻击效果。在CIFAR-10上,针对目标攻击成功率(ASR)在70%至90%之间的分段线性估计表明,与DBA相比,FDBA将所需的中毒比例降低了37.4%至48.4%。在非独立同分布(Non-IID)场景下,FDBA在极端异质性下保留了其IID攻击性能的84.7%,而DBA则降至73.5%,且该框架成功绕过了主流防御机制。本研究为联邦学习安全提供了新的见解,并强调了细粒度分布式攻击所带来的潜在威胁和防御挑战。

英文摘要

Federated learning, as a privacy-preserving distributed machine learning paradigm, faces significant threats from backdoor attacks. Compared to centralized attacks, distributed backdoor attacks are more harmful but require more poisoned samples to compensate for the loss of trigger strength due to decomposition. Fixed trigger patterns are also easily detected by robust aggregation algorithms, increasing the risk of attack exposure. To address these challenges, we propose a fine-grained distributed backdoor attack framework (FDBA). This framework uses dynamic trigger generation and embedding vector optimization to perform attacks with fewer poisoned samples. First, we design a dynamic trigger generation method based on image edge structures using the Canny algorithm to extract edge features, which are then injected with Laplacian noise. RGB channel decomposition is applied for covert adaptation of the distributed trigger, reducing detection chances. Second, we introduce an embedding vector contrastive learning strategy that forces poisoned samples to approach the target class center in the feature space, enhancing attack effectiveness. On CIFAR-10, piecewise-linear estimates for target ASRs between 70\% and 90\% show that FDBA reduces the required poisoning ratio by 37.4\%--48.4\% compared with DBA. In non-independent and identically distributed (Non-IID) scenarios, FDBA retains 84.7\% of its IID attack performance under extreme heterogeneity, whereas DBA drops to 73.5\%, and the framework successfully bypasses mainstream defense mechanisms. This study offers new insights into federated learning security and emphasizes the potential threats and defense challenges posed by fine-grained distributed attacks.

发表机构

  • Faculty of Applied Sciences, Macao Polytechnic University(澳门理工大学应用科学学院)
  • Faculty of Cyberspace Security, Guangzhou University of Software(广州软件学院网络空间安全学院)
  • School of Engineering and Technology, Central Queensland University(中央昆士兰大学工程与技术学院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑