发表机构
James Madison University(詹姆斯·麦迪逊大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对联邦GPS欺骗检测中客户端自报准确率的攻击漏洞,提出接收域行为探测方法,基于反事实样本加权客户端,在诚实多数下有效降低后门影响并识别被入侵者。
AI 中文摘要
联邦学习使无人机机群无需任何飞机的原始接收器数据离开飞机即可训练共享的GPS欺骗检测器,且近期若干无人机联邦学习设计根据每个客户端报告的自身验证准确性来对其加权。我们证明这种自我报告是可利用的攻击杠杆:十个客户端中两个被入侵的客户端毒化部分数据、缩放其更新并夸大其报告的准确性,可将后门提升提高至+0.3036,高于相同攻击在未撒谎时达到的效果。我们提出接收域行为探测,其中协调器在由将每个判别性GPS特征驱动至良性值而构建的反事实欺骗样本上评估每个提交的模型,根据模型的行为而非其声称来加权客户端。在独立同分布客户端下,这将攻击者引起的提升降低至-0.0265,与诚实机群在统计上不可区分,同时标记出被入侵的飞机。与拜占庭鲁棒聚合不同,它不需要精确的攻击者数量,只需诚实多数:当真实数量超过配置值时,Multi-Krum从+0.0061退化至+0.2837,而我们的方法保持接近基线。评估使用一个划分成模拟客户端的公共单接收器数据集;我们还报告了机制在强客户端异质性下失效的情况。
英文摘要
Federated learning lets a UAV fleet train a shared GPS spoofing detector without raw receiver data leaving any aircraft, and several recent UAV-FL designs weight each client by the validation accuracy it reports about itself. We show this self-report is an exploitable attack lever: two compromised clients of ten that poison part of their data, scale their updates, and inflate their reported accuracy raise backdoor lift to +0.3036, higher than the same attack achieves without lying. We propose receiver-domain behavioral probing, in which the coordinator evaluates every submitted model on counterfactual spoofed samples built by driving each discriminative GPS feature to a benign value, weighting clients by what their models do rather than what they claim. Under independent and identically distributed clients this reduces attacker-induced lift to -0.0265, statistically indistinguishable from an honest fleet, while flagging the compromised aircraft. Unlike Byzantine-robust aggregation it needs no exact attacker count, only an honest majority: when the true count exceeds the configured value, Multi-Krum degrades from +0.0061 to +0.2837 while ours stays near baseline. Evaluation uses one public single-receiver dataset partitioned into simulated clients; we also report where the mechanism fails, under strong client heterogeneity.