发表机构
University of Murcia(穆尔西亚大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
DecoyTrace提出一种针对无服务器去中心化联邦学习的主动欺骗防御,通过移动诱饵节点生成混沌诱饵挑战并传播双模型,实现投毒来源隔离与模型恢复,在多种数据集和拓扑下有效恢复效用并降低资源消耗。
AI 中文摘要
去中心化联邦学习(DFL)消除了中央聚合服务器,减少了传统针对攻击的防御所依赖的单一观察点。因此,点对点网络容易受到包含后门或语义投毒的恶意更新的攻击,因为此类更新在参数空间中可能保持接近良性更新,但行为却截然不同。这可能会规避基于被动参数检查的防御。然而,现有的基于欺骗的防御主要针对集中式联邦学习设计,并未在严格无服务器的DFL中联合解决本地观察、投毒传播、来源归因和遏制问题。为解决这些局限性,本文提出了DecoyTrace,一种针对严格无服务器DFL环境的主动网络欺骗防御。DecoyTrace部署了一个移动的诱饵节点(DecoyNode),利用混沌映射生成诱饵挑战,基于邻居信任传播双模型(干净模型与诱饵模型),并使用三态语义指标对其进行评估。确认后,分布式协议会隔离攻击源并执行模型重置或恢复以保持训练进度。在NEBULA平台上跨六十种配置(五种数据集、三种拓扑和四种攻击/防御场景)进行评估,DecoyTrace系统性地恢复了损失效用。在MNIST/FashionMNIST上,F1分数保持在基线的0.03以内(缓解了高达0.37的下降),在EMNIST和CIFAR-100上达到或超过基线,在CIFAR-10(评估中最具视觉复杂性的卷积场景)上保持在基线以下0.05至0.10之间。此外,遏制措施将CPU和网络使用率降低了多达三分之二。这些结果证明了在DFL中统一欺骗、识别和遏制的可行性,同时也指出了其在复杂任务和多吸引子威胁模型中的局限性。
英文摘要
Decentralized Federated Learning (DFL) eliminates the central aggregation server, reducing the single point of observation that traditional defenses against attacks rely on. As a result, peer-to-peer networks become exposed to malicious updates containing backdoors or semantic poisoning, since such updates can remain close to benign ones in the parameter space while behaving very differently. This may evade defenses based on passive parameter inspection. However, existing deception-based defenses have mainly been designed for centralized FL and do not jointly address local observation, poisoning propagation, source attribution, and containment in strictly serverless DFL. To address these limitations, this paper presents DecoyTrace, a proactive cyber deception-based defense for strictly serverless DFL environments. DecoyTrace deploys a mobile DecoyNode that generates decoy challenges using chaotic maps, disseminates a dual model (clean vs. decoy) based on neighbor trust, and evaluates them using three-state semantic metrics. Upon confirmation, a distributed protocol isolates the source and performs a model reset or recovery to preserve training progress. Evaluated across sixty configurations on the NEBULA platform (five datasets, three topologies, and four attack/defense scenarios), DecoyTrace systematically restores lost utility. The F1-score remains within 0.03 of the baseline on MNIST/FashionMNIST (mitigating drops of up to 0.37), matches or exceeds the baseline on EMNIST and CIFAR-100, and remains between 0.05 and 0.10 below the baseline on CIFAR-10, the most visually complex convolutional scenario evaluated. Furthermore, containment reduces CPU and network usage by up to two-thirds. These results demonstrate the feasibility of unifying deception, identification, and containment in DFL, while also identifying its limitations in complex tasks and multi-attractor threat models.
Comments38 pages