Federated learning (FL) has been introduced to enable a large number of clients, possibly mobile devices, to collaborate on generating a generalized machine learning model thanks to utilizing a larger number of local samples without sharing to offer certain privacy to collaborating clients. However, due to the participation of a large number of clients, it is often difficult to profile and verify each client, which leads to a security threat that malicious participants may hamper the accuracy of the trained model by conveying poisoned models during the training. Hence, the aggregation framework at the parameter server also needs to minimize the detrimental effects of these malicious clients. A plethora of attack and defence strategies have been analyzed in the literature. However, often the Byzantine problem is analyzed solely from the outlier detection perspective, being oblivious to the topology of neural networks (NNs). In the scope of this work, we argue that by extracting certain side information specific to the NN topology, one can design stronger attacks. Hence, inspired by the sparse neural networks, we introduce a hybrid sparse Byzantine attack that is composed of two parts: one exhibiting a sparse nature and attacking only certain NN locations with higher sensitivity, and the other being more silent but accumulating over time, where each ideally targets a different type of defence mechanism, and together they form a strong but imperceptible attack. Finally, we show through extensive simulations that the proposed hybrid Byzantine attack is effective against 8 different defence methods.
翻译:联邦学习(FL)的引入使得大量客户端(可能是移动设备)能够协作生成泛化的机器学习模型,其优势在于利用大量本地样本而无需共享数据,从而为协作客户端提供一定隐私保护。然而,由于大量客户端的参与,通常难以对每个客户端进行 profiling 和验证,这导致一种安全威胁:恶意参与者可能在训练过程中通过传递中毒模型来降低训练模型的准确性。因此,参数服务器处的聚合框架也需要最小化这些恶意客户端的有害影响。文献中已分析了大量攻击与防御策略,但拜占庭问题通常仅从异常检测的角度进行分析,忽略了神经网络(NN)的拓扑结构。在本工作中,我们认为通过提取与NN拓扑相关的特定侧信息,可以设计出更强的攻击。受稀疏神经网络的启发,我们引入了一种混合稀疏拜占庭攻击,该攻击由两部分组成:一部分具有稀疏性,仅攻击NN中灵敏度较高的特定位置;另一部分则更为隐蔽,但随时间累积。这两部分各自针对不同类型的防御机制,共同构成一种强大且难以察觉的攻击。最后,通过大量仿真验证,所提出的混合拜占庭攻击对8种不同的防御方法均有效。