引用本文:赵亚茹,张建标,曹益皓,黄浩翔.云边联邦学习系统下抗投毒攻击的防御方法.软件学报,2025,36(9):4250-4270
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 1748次   下载 2169 本文二维码信息
码上扫一扫!
分享到: 微信 更多
云边联邦学习系统下抗投毒攻击的防御方法
赵亚茹1,2, 张建标1,2, 曹益皓1,2, 黄浩翔1,2
1.北京工业大学 计算机学院, 北京 100124;2.可信计算北京市重点实验室 (北京工业大学), 北京 100124
摘要:
随着海量数据的涌现和智能应用需求的日益增长, 保障数据安全成为提高数据质量、实现数据价值的重要举措. 其中, 云边端架构是高效处理和优化数据的新兴技术, 联邦学习(federated learning, FL)作为一个高效的去中心化的机器学习范式, 能够为数据提供隐私保护, 近年来引起了学术界及工业界的广泛关注. 然而, 联邦学习展示出了固有的脆弱性使其易于遭受投毒攻击. 现有绝大多数抵抗投毒攻击的防御方法依赖于连续更新空间, 但在实际场景中面向灵活的攻击方式和攻击场景可能是欠鲁棒的. 鉴于此, 提出一种面向云边联邦学习系统(cloud-edge FL, CEFL)抵抗投毒攻击的防御方法FedDiscrete. 其关键思想是在客户端利用网络模型边的分数计算本地排名, 实现离散更新空间的创建. 进一步地, 为了兼顾参与FL任务的客户端之间的公平性, 引入贡献度指标, 这样, FedDiscrete能够通过分配更新后的全局排名对可能的攻击者实施惩罚. 广泛的实验结果表明所提方法在抵抗投毒攻击方面表现出显著的优势和鲁棒性, 且适用于独立同分布(IID)和非独立同分布(non-IID)场景, 能够为CEFL系统提供保护.
关键词:  联邦学习  投毒攻击  防御策略  离散更新空间  云边端架构
DOI:10.13328/j.cnki.jos.007266
分类号:TP309
基金项目:北京市自然科学基金(M21039)
Defense Method Against Poisoning Attacks in Cloud-edge Federated Learning Systems
ZHAO Ya-Ru1,2, ZHANG Jian-Biao1,2, CAO Yi-Hao1,2, HUANG Hao-Xiang1,2
1.College of Computer Science, Beijing University of Technology, Beijing 100124, China;2.Beijing Key Laboratory of Trusted Computing (Beijing University of Technology), Beijing 100124, China
Abstract:
With the proliferation of massive data and the ever-growing demand for intelligent applications, ensuring data security has become a critical measure for enhancing data quality and realizing data value. The cloud-edge-client architecture has emerged as a promising technology for efficient data processing and optimization. Federated learning (FL), an efficient decentralized machine learning paradigm that can provide privacy protection for data, has garnered extensive attention from academia and industry in recent years. However, FL has demonstrated inherent vulnerabilities that render it highly susceptible to poisoning attacks. Most existing methods for defending against poisoning attacks rely on continuously updated space, but in practical scenarios, those methods may be less robust when facing flexible attack strategies and varied attack scenarios. Therefore, this study proposes FedDiscrete, a defense method for resisting poisoning attacks in cloud-edge FL (CEFL) systems. The key idea is to compute local rankings on the client side using the scores of network model edges to create discrete update space. To ensure fairness among clients participating in the FL task, this study also introduces a contribution metric. In this way, FedDiscrete can penalize potential attackers by allocating updated global rankings. Extensive experiments demonstrate that the proposed method exhibits significant advantages and robustness against poisoning attacks, and is applicable to both independent and identically distributed (IID) and non-IID scenarios, providing protection for CEFL systems.
Key words:  federated learning (FL)  poisoning attack  defense strategy  discrete update space  cloud-edge-client architecture

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: