In a federated learning (FL) system, malicious participants can easily embed backdoors into the aggregated model while maintaining the model's performance on the main task. To this end, various defenses, including training stage aggregation-based defenses and post-training mitigation defenses, have been proposed recently. While these defenses obtain reasonable performance against existing backdoor attacks, which are mainly heuristics based, we show that they are insufficient in the face of more advanced attacks. In particular, we propose a general reinforcement learning-based backdoor attack framework where the attacker first trains a (non-myopic) attack policy using a simulator built upon its local data and common knowledge on the FL system, which is then applied during actual FL training. Our attack framework is both adaptive and flexible and achieves strong attack performance and durability even under state-of-the-art defenses.
翻译:在联邦学习系统中,恶意参与者可以轻易地将后门嵌入到聚合模型中,同时保持模型在主任务上的性能。为此,近期提出了多种防御措施,包括基于训练阶段聚合的防御和训练后缓解防御。尽管这些防御方法在应对现有(主要基于启发式)后门攻击时表现合理,但我们表明它们在面对更先进的攻击时仍显不足。特别地,我们提出了一种通用的基于强化学习的后门攻击框架,其中攻击者首先利用本地数据和联邦系统的通用知识构建模拟器,训练出一种(非短视的)攻击策略,随后将其应用于实际联邦训练中。我们的攻击框架兼具适应性和灵活性,即使在最先进的防御措施下也能实现强大的攻击性能和持久性。