Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning

Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning
复制标题

DOI:
10.14722/ndss.2021.24498
复制
发表时间:
2021
期刊:
Proceedings 2021 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Virat Shejwalkar;Amir Houmansadr
Virat Shejwalkar;Amir Houmansadr
中科院分区:
其他
文献类型:
--
作者:
Virat Shejwalkar;Amir Houmansadr

文献摘要

被引文献

相似文献

- 联邦学习(FL)使许多数据所有者(例如,移动的设备)来训练联合ML模型(例如,下一个单词预测分类器),而无需共享其私有训练数据。然而,已知FL易受恶意参与者的中毒攻击(例如,对手拥有的移动的设备),其目的在于通过在联合训练过程期间发送恶意输入来妨碍联合训练的模型的准确性。在本文中,我们提出了一个通用的框架模型中毒攻击FL。我们表明,我们的框架导致中毒攻击,大大优于最先进的模型中毒攻击的大利润率。例如,我们的攻击导致1。与以前发现的中毒攻击相比,FL模型的准确性降低了5倍到60倍。我们的工作表明,现有的拜占庭鲁棒FL算法比以前认为的更容易受到模型中毒的影响。受此启发,我们设计了一种针对FL中毒的防御方法,称为分而治之(DnC)。我们证明了DnC在击败模型中毒攻击方面优于所有现有的Byzantine-robust FL算法,具体来说,它是2。在我们使用不同数据集和模型的实验中,弹性提高了5倍到12倍。
—Federated learning (FL) enables many data owners (e.g., mobile devices) to train a joint ML model (e.g., a next-word prediction classifier) without the need of sharing their private training data. However, FL is known to be susceptible to poisoning attacks by malicious participants (e.g., adversary-owned mobile devices) who aim at hampering the accuracy of the jointly trained model through sending malicious inputs during the federated training process. In this paper, we present a generic framework for model poisoning attacks on FL. We show that our framework leads to poisoning attacks that substantially outperform state-of-the-art model poisoning attacks by large margins. For instance, our attacks result in 1 . 5 × to 60 × higher reductions in the accuracy of FL models compared to previously discovered poisoning attacks. Our work demonstrates that existing Byzantine-robust FL algorithms are significantly more susceptible to model poisoning than previously thought. Motivated by this, we design a defense against FL poisoning, called divide-and-conquer (DnC). We demonstrate that DnC outperforms all existing Byzantine-robust FL algorithms in defeating model poisoning attacks, specifically, it is 2 . 5 × to 12 × more resilient in our experiments with different datasets and models.