Bayesian Optimization-Driven Adversarial Poisoning Attacks Against Distributed Learning

Bayesian Optimization-Driven Adversarial Poisoning Attacks Against Distributed Learning
复制标题

DOI:
10.1109/access.2023.3304541
复制
发表时间:
2023
期刊:
影响因子:
3.9
通讯作者:
Marios Aristodemou;Xiaolan Liu;S. Lambotharan;Basil AsSadhan
Marios Aristodemou;Xiaolan Liu;S. Lambotharan;Basil AsSadhan
中科院分区:
计算机科学3区
文献类型:
--
作者:
Marios Aristodemou;Xiaolan Liu;S. Lambotharan;Basil AsSadhan

文献摘要

被引文献

相似文献

元宇宙被设想为下一代以人为本的互联网,可以为用户提供身临其境的体验,在医疗保健、教育、娱乐和行业中有广泛的应用。这些应用程序需要分析包含隐私和敏感信息的大量数据。保护隐私的一个潜在解决方案是部署分布式学习框架,包括联邦学习(FL)和分裂学习(SL),因为它们能够解决隐私泄露和分析个性化数据,而无需共享原始数据。然而,已知FL和SL仍然容易受到对抗性中毒攻击。在本文中,我们分析了Metaverse服务中隐私保护机制的关键问题。我们开发了一种基于贝叶斯优化的新型中毒攻击,以模拟针对FL(BO-FLPA)和SL(BO-SLPA)的对抗行为,这对于未来开发有效的防御算法非常重要。具体来说,我们开发了一个层优化方法,使用黑盒优化的直觉,假设预测的不确定性和层优化参数之间有一个函数。该优化的结果为隐藏层提供了最佳权重参数,例如FL的第一层或第二层,以及SL的第一层。数值结果表明,在FL和SL中,中毒的隐藏层有能力增加模型对对抗性攻击的敏感性,即预测置信度低或预测的概率密度函数偏差较大。
Metaverse is envisioned to be the next-generation human-centric Internet which can offer an immersive experience for users with a broad application in healthcare, education, entertainment, and industries. These applications require the analysis of massive data that contains private and sensitive information. A potential solution to preserving privacy is deploying distributed learning frameworks, including federated learning (FL) and split learning (SL), due to their ability to address privacy leakage and analyze personalised data without sharing raw data. However, it is known that FL and SL are still susceptible to adversarial poisoning attacks. In this paper, we analyse such critical issues for the privacy-preserving mechanism in Metaverse services. We develop a novel poisoning attack based on Bayesian optimisation to emulate the adversarial behaviour against FL (BO-FLPA) and SL (BO-SLPA) which is important for the development of effective defense algorithms in the future. Specifically, we develop a layer optimisation method using the intuition of black-box optimisation with assuming that there is a function between the prediction’s uncertainty and layer optimisation parameters. The result of this optimisation provides the optimal weight parameters for the hidden layer, such as the first or the second layer for FL, and the first layer for SL. Numerical results demonstrate that in both FL and SL, the poisoned hidden layers have the ability to increase the susceptibility of the model to adversarial attacks in terms of prediction with low confidence or having a larger deviation of the probability density function of the predictions.