Due to the greatly improved capabilities of devices, massive data, and increasing concern about data privacy, Federated Learning (FL) has been increasingly considered for applications to wireless communication networks (WCNs). Wireless FL (WFL) is a distributed method of training a global deep learning model in which a large number of participants each train a local model on their training datasets and then upload the local model updates to a central server. However, in general, non-independent and identically distributed (non-IID) data of WCNs raises concerns about robustness, as a malicious participant could potentially inject a "backdoor" into the global model by uploading poisoned data or models over WCN. This could cause the model to misclassify malicious inputs as a specific target class while behaving normally with benign inputs. This survey provides a comprehensive review of the latest backdoor attacks and defense mechanisms. It classifies them according to their targets (data poisoning or model poisoning), the attack phase (local data collection, training, or aggregation), and defense stage (local training, before aggregation, during aggregation, or after aggregation). The strengths and limitations of existing attack strategies and defense mechanisms are analyzed in detail. Comparisons of existing attack methods and defense designs are carried out, pointing to noteworthy findings, open challenges, and potential future research directions related to security and privacy of WFL.
翻译:随着设备能力的大幅提升、海量数据的涌现以及人们对数据隐私日益增长的关注,联邦学习(FL)在无线通信网络(WCNs)中的应用日益受到重视。无线联邦学习(WFL)是一种分布式训练全局深度学习模型的方法,其中大量参与者各自在其训练数据集上训练本地模型,随后将本地模型更新上传至中心服务器。然而,通常无线通信网络中非独立同分布(non-IID)的数据引发了鲁棒性方面的担忧,因为恶意参与者可能通过在无线通信网络上上传投毒数据或模型,向全局模型注入“后门”。这可能导致模型将恶意输入错误分类为特定目标类别,而对良性输入则表现正常。本综述全面回顾了最新的后门攻击与防御机制。根据攻击目标(数据投毒或模型投毒)、攻击阶段(本地数据收集、训练或聚合)以及防御阶段(本地训练、聚合前、聚合中或聚合后)对其进行分类。详细分析了现有攻击策略与防御机制的优势与局限性。对现有攻击方法与防御设计进行了比较,指出了与WFL安全及隐私相关的值得关注的发现、开放性挑战以及潜在的未来研究方向。