Learning to Backdoor Federated Learning

Learning to Backdoor Federated Learning
复制标题

DOI:
10.48550/arxiv.2303.03320
复制
发表时间:
2023-03
期刊:
ArXiv
影响因子:
--
通讯作者:
Henger Li;Chen Wu;Senchun Zhu;Zizhan Zheng
Henger Li;Chen Wu;Senchun Zhu;Zizhan Zheng
中科院分区:
其他
文献类型:
--
作者:
Henger Li;Chen Wu;Senchun Zhu;Zizhan Zheng

文献摘要

相似文献

在联合学习(FL)系统中,恶意参与者可以很容易地在聚合模型中嵌入后门,同时保持模型在主任务上的性能。为此,最近提出了各种防御措施,包括训练阶段基于聚合的防御措施和训练后缓解防御措施。虽然这些防御针对现有的后门攻击获得了合理的性能,这些后门攻击主要是基于启发式的,但我们表明,面对更高级的攻击,它们是不够的。特别是,我们提出了一种通用的基于强化学习的后门攻击框架,其中攻击者首先使用基于其本地数据和FL系统常识的模拟器来训练(非近视)攻击策略,然后将其应用于实际的FL训练。我们的攻击框架具有自适应性和灵活性,即使在最先进的防御下也能实现强大的攻击性能和持久性。
In a federated learning (FL) system, malicious participants can easily embed backdoors into the aggregated model while maintaining the model's performance on the main task. To this end, various defenses, including training stage aggregation-based defenses and post-training mitigation defenses, have been proposed recently. While these defenses obtain reasonable performance against existing backdoor attacks, which are mainly heuristics based, we show that they are insufficient in the face of more advanced attacks. In particular, we propose a general reinforcement learning-based backdoor attack framework where the attacker first trains a (non-myopic) attack policy using a simulator built upon its local data and common knowledge on the FL system, which is then applied during actual FL training. Our attack framework is both adaptive and flexible and achieves strong attack performance and durability even under state-of-the-art defenses.