arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

当客户端被编排:通过高效防御的战略性梯度操纵击败联邦学习服务器

When Clients Are Orchestrated: Strategic Gradient Manipulation to Defeat Federated Learning Servers with Efficient Defense

Mohamed Shaaban, Ahmed Abdelnaby, Mohamed Elmahallawy

arXiv 2609.27124首次发表:更新:

发表机构

Washington State University(华盛顿州立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出Fed-ADR攻击框架,揭示动态自适应客户端协作可绕过联邦学习防御,并设计检测与恢复机制,在几轮内恢复准确率至90%以上,计算开销降低至少20倍。

AI 中文摘要

联邦学习通过交换模型更新(而非原始数据)与中央参数服务器(PS)实现分散式模型训练。尽管现有的大多数防御主要假设静态或独立行动的对手,我们揭示了一类新的动态自适应攻击,能够系统地绕过此类保护。我们提出了Fed-ADR,一个整体攻击框架,其中恶意编排服务器(OS)动态协调一组异构的对抗性客户端,包括定向和非定向攻击者。通过OS的实时协调,恶意客户端策略性地调整其梯度更新,以规避PS部署的防御,同时要么严重降低全局模型性能,要么将训练引导至对抗性目标。为缓解此威胁,我们提供了一种检测机制,该机制从历史更新中估计每个客户端的真实梯度,从而在无额外开销的情况下实时检测协调的恶意行为。我们进一步引入了一种原位恢复机制,该机制无需重启训练即可恢复全局模型性能,保持收敛并最小化恢复时间。在MNIST、Fashion-MNIST和CIFAR-10基准数据集上的综合实验表明,Fed-ADR的攻击方案可将全局准确率从90%以上降至10%以下,绕过多种最先进的防御。当采用我们的检测和恢复模块时,它们能在几轮内识别恶意客户端并将准确率恢复到90%以上,且成本远低于从头重新训练——实现计算开销至少减少20倍。

英文摘要

Federated Learning enables decentralized model training by exchanging model updates--rather than raw data--with a central parameter server (PS). While most of the existing defenses primarily assume static or independently acting adversaries, we reveal a new class of dynamically adaptive attacks that systematically bypass such protections. We propose Fed-ADR, a holistic attack framework in which a malicious orchestrator server (OS) dynamically coordinates a heterogeneous set of adversarial clients, including both targeted and untargeted attackers. Through real-time coordination by the OS, malicious clients strategically adapt their gradient updates to evade defenses deployed by the PS, while either severely degrading global model performance or steering training toward adversarial objectives.To mitigate this threat, we offer a detection mechanism that estimates each client's true gradient from historical updates, enabling real-time detection of coordinated malicious behavior without additional overhead. We further introduce an in-situ recovery mechanism that restores global model performance without restarting training, preserving convergence and minimizing recovery time. Comprehensive experiments on MNIST, Fashion-MNIST, and CIFAR-10 benchmark datasets demonstrate that Fed-ADR's attack scheme can reduce global accuracy from over 90% to below 10%, bypassing several state-of-the-art defenses. When our detection and recovery modules are employed, they identify malicious clients and restore accuracy to over 90% within a few rounds, at a substantially lower cost than retraining from scratch--achieving a reduction of at least 20x in computational overhead.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑