Learning to Attack Federated Learning: A Model-based Reinforcement Learning Attack Framework

Learning to Attack Federated Learning: A Model-based Reinforcement Learning Attack Framework
复制标题

DOI:
--
复制
发表时间:
2022
期刊:
--
影响因子:
--
通讯作者:
Henger Li;Xiaolin Sun;Zizhan Zheng
Henger Li;Xiaolin Sun;Zizhan Zheng
中科院分区:
其他
文献类型:
--
作者:
Henger Li;Xiaolin Sun;Zizhan Zheng

文献摘要

被引文献

相似文献

提出了一种基于模型的强化学习框架,用于派生针对联邦学习系统的非目标中毒攻击。我们的框架首先使用来自服务器的模型更新来近似客户端的聚合数据的分布。然后,学习的分布被用来构建FL环境的模拟器,该模拟器用于通过强化学习来学习自适应攻击策略。我们的框架能够自动学习强攻击,即使服务器采用了健壮的聚集规则。我们进一步推导出攻击者由于不准确的分布估计而造成的性能损失的上界。在真实世界数据集上的实验结果表明,该攻击框架的性能明显优于最新的中毒攻击。这表明了为FL系统开发自适应防御的重要性。
We propose a model-based reinforcement learning framework to derive untargeted poisoning attacks against federated learning (FL) systems. Our framework first approximates the distribution of the clients’ aggregated data using model updates from the server. The learned distribution is then used to build a simulator of the FL environment, which is utilized to learn an adaptive attack policy through reinforcement learning. Our framework is capable of learning strong attacks automatically even when the server adopts a robust aggregation rule. We further derive an upper bound on the attacker’s performance loss due to inaccurate distribution estimation. Experimental results on real-world datasets demonstrate that the proposed attack framework significantly outperforms state-of-the-art poisoning attacks. This indicates the importance of developing adaptive defenses for FL systems.