arrow
Return

Covert Model Poisoning Against Federated Learning: Algorithm Design and Optimization

delete2024-05-01
delete2
delete
OA
AI
韦康 cover
韦康 (Kang Wei)
李俊 (Jun Li) *
M
Ming Ding
C
Chuan Ma
Y
Yo–Seb Jeon
H
H. Vincent Poor
DOI:10.1109/TDSC.2023.3274119delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Federated learning (FL), as a type of distributed machine learning, is vulnerable to external attacks during parameter transmissions between learning agents and a model aggregator. In particular, malicious participant clients in FL can purposefully craft their uploaded model parameters to manipulate system outputs, which is know as a model poisoning (MP) attack. In this paper, we propose effective MP algorithms to attack the classical defensive aggregation Krum at the aggregator. The proposed algorithms are designed to evade detection, i.e., covert MP (CMP). Specifically, we first formulate the MP as an optimization problem by minimizing the Euclidean distance between the manipulated model and designated one, constrained by Krum. Then, we develop CMP algorithms against Krum based on the solutions of this optimization problem. Furthermore, to reduce the optimization complexity, we propose low complexity CMP algorithms having only a slight performance degradation. Our experimental results demonstrate that the proposed CMP algorithms are effective and can substantially outperform existing attack mechanisms, such as Arjun's attack and the label flipping attack. More specifically, our original CMP can achieve a high rate of the attacker's accuracy ($\approx 90\%$approximate to 90%). For example, in our experiments using the MNIST dataset, the proposed CMP attacking algorithm against Krum can successfully manipulate the aggregated model to incorrectly classify a given digit as a different one (e.g., 9 as 8). Meanwhile, our CMP algorithm with an approximated constraint can achieve a rate of 87% in terms of the attacker's accuracy (attacker-desired results), with a 73% complexity reduction compared to the original CMP.
Keywords:
Federated learning
model poisoning attack
robust aggregation

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

P
Princeton University
Scholars:
2.1W
Papers: 2.3W
Citations: 5.1W
Z
Zhejiang Laboratory
Scholars:
1.8K
Papers: 1.7K
Citations: 0
researcher View more organizations