Rethinking the Transferable Adversarial Attacks and Robust Defense in Federated Learning

📅 2026-08-25
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文分析了联邦学习中对抗样本的可迁移性,并设计了一种基于对抗训练的防御机制以缓解可迁移对抗样本攻击。
📝 Abstract
The development of federated learning (FL) techniques has helped improve the privacy preservation of users' data and extended the applications of machine learning models. However, the involvement of a large number of users in FL also creates open opportunities for different adversaries, such as poisoning attacks, Byzantine attacks, and adversarial example attacks. Yet, recent research has disclosed that existing poisoning attacks and Byzantine attacks can not achieve satisfactory penetration in realistic FL scenarios caused by strong assumptions, \textit{e.g.,} client selection rate, and the ratio of malicious attackers. In this paper, the transferability of adversarial examples among different client models is analyzed to understand the relation between adversarial examples and clients' data distribution. Moreover, to mitigate the attacks of transferable adversarial examples, we design a defense mechanism stemming from the transferability of model robustness by adversarial training. As a result, through theoretical analysis of transferability, we gain insights into adversarial examples and the vulnerability of federated learning systems. Our proposed adversarial attack and defense methods are evaluated via real-life datasets in various settings to show their performance over the existing state-of-the-art methods.
Problem

Research questions and friction points this paper is trying to address.

adversarial examples
federated learning
transferability
model robustness
client data distribution
Innovation

Methods, ideas, or system contributions that make the work stand out.

adversarial examples
transferability
federated learning
defense mechanism
adversarial training
Zuobin Xiong
Zuobin Xiong
Assistant Professor, Dept. of Computer Science, University of Nevada, Las Vegas
Distributed LearningData PrivacyMachine UnlearningGenerative AI
D
Deval Mukherjee
Department of Computer Science, University of Nevada Las Vegas, Las Vegas, USA
H
Homook Cho
Cyber Security Research Center at KAIST, Daejeon, South Korea
W
Wei Li
Department of Computer Science, Georgia State University, Atlanta, Georgia, USA