节点文献
基于触发协同与动态优化的联邦学习快速投毒攻击方法研究
Research on federated learning fast poisoning attack method based on trigger collaboration and dynamic optimization
【摘要】 联邦学习通过多方协同训练而无需共享私有数据,有效解决了数据隐私和数据孤岛问题。然而,由于联邦学习的分布式特性,导致其容易受到各种恶意攻击。大多数现有的攻击方法通常仅依赖单一触发器,并且无法在训练过程中根据训练轮数动态调整攻击强度,导致攻击效果不佳和隐蔽性等问题。文中提出一种基于触发协同与动态优化的联邦学习快速投毒攻击方法。首先,在本地数据准备阶段使用静态触发器实现数据投毒,进一步在模型训练阶段使用动态触发器实现噪声注入;然后,在攻击过程中通过调整攻击强度和权重比例,灵活应用自适应后门攻击(A3FL)和后门个性化联邦学习(BAPFL)的分层策略,能够在训练过程中平衡攻击成功率与系统稳定性。通过在CIFAR-10数据集上的实验表明,该方法在攻击成功率、运行时间、测试准确率与持久性等多维度上均优于传统方法,为未来人工智能安全研究提供了一种新思路。
【Abstract】 Federated learning effectively solves the problem of data privacy and data silos by multi-party collaborative training without sharing private data. However, the federated learning is vulnerable to various malicious attacks due to its distributed nature. At present, most of the existing attack methods usually rely on a single trigger, and their attack intensities cannot be adjusted dynamically according to the number of training rounds during the process of training, resulting in limited attack effectiveness and concealment. This paper proposes a federated learning fast poisoning attack method based on trigger coordination and dynamic optimization. Firstly, static triggers are used to poison the data in the stage of local data preparation, and dynamic triggers are used to inject noise in the stage of model training. Then, by adjusting the attack intensity and the weight ratio, the hierarchical strategies of adversarially adaptive backdoor attacks to federated learning(A3 FL) and backdoor personalized federated learning(BAPFL) are applied flexibly. It can balance the success rate of attacks and the system stability during training. Experimental results on the CIFAR-10 dataset show that the proposed method is superior to the traditional methods in multiple dimensions such as attack success rate, running time, test accuracy rate and persistence. To sum up, it provides a new idea for future AI security research.
【Key words】 federated learning; poisoning attack; dynamic attack; dynamic trigger; static trigger; attack persistence;
- 【文献出处】 现代电子技术 ,Modern Electronic Technique , 编辑部邮箱 ,2026年03期
- 【分类号】TP309;TP181
- 【下载频次】18