节点文献
面向联邦学习的抗合谋攻击方法研究
Research on Anti-Collusion Attack Methods for Federated Learning
【作者】 张晶;
【导师】 郭成;
【作者基本信息】 大连理工大学 , 软件工程, 2022, 硕士
【摘要】 当前人工智能的安全受到普遍的关注,多种防治措施在积极开展。联邦学习主要从技术层面入手,着重探究其中的隐私性与安全性。一方面,联邦学习方案大多都采用同一密钥的加密算法,无法抵御恶意服务器和参与者的合谋攻击。同时,针对模型梯度的攻击也会导致私有数据泄露。另一方面,参与者之间存在资源和数据异构,导致其对模型性能贡献程度不同,合理评估参与者性能并确定选择方法也是一个值得关注的问题。本文提出了一种联邦学习场景下的数据安全共享方案,利用传输深度学习模型权重可以达到抵御恶意服务器和参与者合谋攻击的目的。安全分析表明恶意者从模型权重反演数据需要求解非线性方程组,但此求解过程往往很难。考虑到不同参与者的数据存在大小不同、分布特征不同等异构性问题,本文设计了一种异构感知的自适应参与者选择方法。该方法根据观察到的训练性能和准确度即时更新分组,以缓解异构对模型训练时间和准确度的影响。通过自适应地选择参与者子集参与训练,一方面能够有效减少了所有参与者参与训练造成的大量通信成本,另一方面也能够剔除异常参与者,减少被恶意攻击的风险。本文基于MNIST和CIFAR10数据集,根据训练时间、模型准确度、传输数据量等多个性能指标对所提出的方案进行了评估。结果表明,本文提出的方案满足安全性要求,并在准确度和时间方面都有所提高。
【Abstract】 At present,the security of artificial intelligence has aroused people’s general concern,prompting the implementation of a number of preventative measures.Federated learning mainly starts from the technical level,focusing on privacy and data security issues.On the one hand,most of the existing federated learning schemes adopt the encryption algorithm with the same key,making them vulnerable to collusion attacks by the malicious cloud server and participants.At the same time,attacks on model gradients can lead to private data leakage.On the other hand,resource heterogeneity and data quantity heterogeneity among the participants,resulting in their different contributions to the model.Reasonable assessment of participant performance and formulation of participant selection methods are also issues that should be paid attention to.In this paper,a data security sharing scheme in the federated learning scenario is proposed,which uses transmission deep learning model weights to resist collusion attacks among malicious servers and participants.Security analysis proves that the data inversed by malicious parties from model weights need to solve nonlinear equations,but this process is often difficult,secure data sharing is achieved.Considering the heterogeneity of different participants,such as different sizes and different distribution features,this paper designs a heterogeneous-aware adaptive participant selection method.The method instantly updates the stratification based on the observed training performance and accuracy to alleviate the impact of heterogeneity on model training time and accuracy.By adaptively selecting a subset of participants to participate in training,on the one hand,a large amount of communication cost caused by all participants participating in the training can be effectively reduced;on the other hand,abnormal participants can also be eliminated,and the risk of malicious attack is reduced.Based on MNIST and CIFAR10 data sets,this paper assesses the proposed scheme in terms of several performance indicators such as training time,model accuracy,and the amount of transmitted data.The results show that the proposed scheme meets the security requirements and improves both in the terms of the accuracy and time.
【Key words】 Federated Learning; Collusion Attack; Participant Selection; Security Privacy; Deep Learning;