引用本文:王瑞锦,王金波,张凤荔,李经纬,李增鹏,陈厅.联邦原型学习的特征图中毒攻击和双重防御机制.软件学报,2025,36(3):1355-1374
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 1784次   下载 2725 本文二维码信息
码上扫一扫!
分享到: 微信 更多
联邦原型学习的特征图中毒攻击和双重防御机制
王瑞锦1, 王金波1, 张凤荔1, 李经纬2, 李增鹏3, 陈厅2
1.电子科技大学 信息与软件工程学院, 四川 成都 610054;2.电子科技大学 计算机科学与工程学院, 四川 成都 611731;3.山东大学 网络空间安全学院, 山东 青岛 266237
摘要:
联邦学习是一种无需用户共享私有数据、以分布式迭代协作训练全局机器学习模型的框架. 目前流行的联邦学习方法FedProto采用抽象类原型(称为特征图)聚合, 优化模型收敛速度和泛化能力. 然而, 该方法未考虑所聚合的特征图的正确性, 而错误的特征图可能导致模型训练失效. 为此, 首先探索针对FedProto的特征图中毒攻击, 论证攻击者只需通过置乱训练数据的标签, 便可将模型的推测准确率至多降低81.72%. 为了抵御上述攻击, 进一步提出双重防御机制, 分别通过全知识蒸馏和特征图甄别排除错误的特征图. 基于真实数据集的实验表明, 防御机制可将受攻击模型的推测准确率提升1–5倍, 且仅增加2%系统运行时间.
关键词:  联邦学习  数据异构  知识蒸馏  特征图中毒攻击  双重防御机制
DOI:10.13328/j.cnki.jos.007183
分类号:TP309
基金项目:国家重点研发计划(2022YFB4501200, 2022YFB3304303); 国家自然科学基金(62271128, 61972073, U2333207); 成都市重点研发支撑计划“揭榜挂帅”项目(2022-JB00-00013-GX); 四川省科技计划重点研发项目(2022ZDZX0004, 2023YFG0029, 2023YFG0150, 2022YFG0212, 2021YFS0391); 四川省科技计划“揭榜挂帅”项目(2023YFG0374, 2023YFG0373); 山东省自然科学基金(ZR2023MF045)
Feature Map Poisoning Attack and Dual Defense Mechanism for Federated Prototype Learning
WANG Rui-Jin1, WANG Jin-Bo1, ZHANG Feng-Li1, LI Jing-Wei2, LI Zeng-Peng3, CHEN Ting2
1.School of Information and Software Engineering, University of Electronic Science and technology of China, Chengdu 610054, China;2.School of Computer Science and Engineering, University of Electronic Science and technology of China, Chengdu 611731, China;3.School of Cyber Science and Technology, Shandong University, Qingdao 266237, China
Abstract:
Federated learning, a framework for training global machine learning models through distributed iterative collaboration without sharing private data, has gained prevalence. FedProto, a widely used federated learning approach, employs abstract class prototypes, termed feature maps, to enhance model convergence speed and generalization capacity. However, this approach overlooks the verification of the aggregated feature maps’ accuracy, risking model training failures due to incorrect feature maps. This study investigates a feature map poisoning attack on FedProto, revealing that malicious actors can degrade inference accuracy by up to 81.72% through tampering with the training data labels. To counter such attacks, we propose a dual defense mechanism utilizing knowledge distillation and feature map validation. Experimental results on authentic datasets demonstrate that this defense strategy can enhance the compromised model inference accuracy by a factor of 1 to 5, with only a marginal 2% increase in operational time.
Key words:  federated learning  data heterogeneous  knowledge distillation  feature map poisoning attack  dual defense mechanism

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: