Federated learning (FL) goes beyond traditional, centralized machine learning by distributing model training among a large collection of edge clients. These clients cooperatively train a global, e.g., cloud-hosted, model without disclosing their local, private training data. The global model is then shared among all the participants which use it for local predictions. In this paper, we put forward a novel attacker model aiming at turning FL systems into covert channels to implement a stealth communication infrastructure. The main intuition is that, during federated training, a malicious sender can poison the global model by submitting purposely crafted examples. Although the effect of the model poisoning is negligible to other participants, and does not alter the overall model performance, it can be observed by a malicious receiver and used to transmit a single bit.
翻译:联邦学习超越了传统集中式机器学习,通过在大量边缘客户端间分布模型训练来实现协作。这些客户端在不泄露本地私有训练数据的前提下,协同训练一个全局模型(例如托管于云端)。随后,该全局模型在所有参与者间共享,供其进行本地预测。本文提出了一种新型攻击者模型,旨在将联邦学习系统转化为隐蔽信道,从而构建秘密通信基础设施。核心思路在于:在联邦训练过程中,恶意发送方可通过提交精心构造的样本污染全局模型。尽管模型投毒对其他参与者的影响微乎其微,且不会改变整体模型性能,但恶意接收方仍可观察到该污染行为,并利用其传输单个比特信息。