联邦学习标签翻转攻击的老虎机动态防御方法

曹越, 许岗, 徐晓东

小型微型计算机系统 ›› 2026, Vol. 47 ›› Issue (9) : 2192 -2198.

小型微型计算机系统 ›› 2026, Vol. 47 ›› Issue (9) : 2192 -2198. DOI: 10.20009/j.cnki.21-1106/TP.2025-0295
算法理论与人工智能

联邦学习标签翻转攻击的老虎机动态防御方法

    曹越, 许岗, 徐晓东
作者信息 +

Defense Method Against Dynamic Label Flipping Attacks in Federated Learning Based on Bandit Algorithm

    CAO Yue, XU Gang, XU Xiaodong
Author information +
文章历史 +

摘要

联邦学习技术作为一种为保护数据隐私设计的分布式机器学习范式,通过聚合客户端本地模型协同训练全局模型.但客户端的分布式特性使得联邦学习系统易受到恶意客户端的标签翻转攻击,且现有防御机制缺乏对动态攻击的应对能力.为此提出FedCCB(Federated Client Choose Bandit,FedCCB)算法,该算法使用上下文老虎机设计客户端上下文信息形成特征向量,借由特征向量动态选择客户端参与模型聚合,依据客户端准确率变化计算奖励并动态调整参数;通过综合评估准确率等因素计算信任分数,并基于信任分数设计加权聚合方式,在模型聚合时为正常客户端赋予更高权重.仿真实验结果表明,在3种不同恶意客户端比例和腐化概率下,FedCCB算法具有较好稳定性的同时平均准确率能够达到89.85%,相比其他算法提高12.85%以上.综上所述,FedCCB算法能有效防御动态标签翻转攻击,显著增强联邦学习系统的鲁棒性,具备高准确率、高稳定性和高收敛速度的优点.

Abstract

Federated learning technology,as a distributed machine learning paradigm designed for data privacy protection,collaboratively trains a global model by aggregating client local models.However,the distributed nature of the client makes federated learning systems vulnerable to label flipping attacks from malicious clients,and existing defense mechanisms lack the ability to respond to dynamic attacks.To this end,the FedCCB (Federated Client Choose Bandit) algorithm is proposed,which uses context slot machines to design client context information to form feature vectors.By using feature vectors,clients are dynamically selected to participate in model aggregation,and rewards are calculated and parameters are dynamically adjusted based on changes in client accuracy; By comprehensively evaluating factors such as accuracy,the trust score is calculated,and a weighted aggregation method is designed based on the trust score to assign higher weights to normal clients during model aggregation.The simulation experiment results show that under three different proportions of malicious clients and corruption probabilities,the FedCCB algorithm has good stability and an average accuracy of 89.85%,which is more than 12.85% higher than other algorithms.In summary,the FedCCB algorithm can effectively defend against dynamic label flipping attacks,significantly enhance the robustness of federated learning systems,and has the advantages of high accuracy,high stability,and fast convergence speed.

关键词

联邦学习 / 标签翻转攻击防御 / 上下文老虎机 / 客户端选择 / 信任分数计算

Key words

federated learning / defense against label flipping attacks / contextual bandit / client selections / trust score calculation

引用本文

引用格式 ▾
曹越, 许岗, 徐晓东. 联邦学习标签翻转攻击的老虎机动态防御方法[J]. 小型微型计算机系统, 2026, 47(9): 2192-2198 DOI:10.20009/j.cnki.21-1106/TP.2025-0295

登录浏览全文

4963

注册一个新账户 忘记密码

参考文献

[1] QAIN W J,SHEN Q N,WU P F,et al.Research progress on privacy-preserving techniques in big data computing environment[J].Chinese Journal of Computers,2022,45(4):669-701.
[2] Li L,Fan Y,Lin K Y.A survey on federated learning[C]//IEEE 16th International Conference on Control & Automation(ICCA),2020:791-796.
[3] Mahon P,Chatzitheofilou I,Dekker A,et al.A federated learning system for precision on cology in europe:digione[J].Nature Medicine,2024,30(2):334-337.
[4] WU W T,WU Y L,LIN W W,et al.Horizontal federated learning:research status,system applications and open challenges[J].Chinese Journal of Computers,2025,48(1):35-67.
[5] GAO Y,CHEN X F,ZHANG Y Y,et al.A survey of attack and defense techniques for federated learning systems[J].Chinese Journal of Computers,2023,46(9):1781-1805.
[6] Ren Q,Zheng Y,Yang C,et al.Shadow backdoor attack:multi-intensity backdoor attack against federated learning[J].Computers & Security,2024,139(5):103740,doi:10.1016/j.cose.2024.103740.
[7] Liu X Y,Li H W,Xu G W,et al.Privacy-enhanced federated learning against poisoning adversaries[J].IEEE Transactions on Information Forensics and Security,2021,16:4574-4588,doi:10.1109/TIFS.2021.3108434.
[8] Yin D,Chen Y D,Ramchandran K,et al.Byzantine-robust distributed learning:towards optimal statistical rates[C]//Proceedings of the 35th International Conference on Machine Learning(ICML),2018:5650-5659.
[9] MA X D,LI Q H,JIANG Q,et al.Byzantine robust federated learning for Non-IID data[J].Journal on Communications,2023,44(6):138-153.
[10] WU L Z,WANG X D,XU T,et al.Defense strategies against poisoning attacks in semi-asynchronous federated learning[J].Netinfo Security,2024,24(10):1578-1585.
[11] Blanchard P,Mhamdi E,Guerraoui R,et al.Machine learning with adversaries:Byzantine tolerant gradient descent[C]//Proceedings of the Neural Information Processing Systems(NeurIPS),2017:119-129.
[12] Shayan M,Fung C,Yoon C,et al.Biscotti:a blockchain system for private and secure federated learning[J].IEEE Transactions on Parallel and Distributed Systems,2021,32(7):1513-1525.
[13] Jin S,Li Y,Chen X,et al.Blockchain-based fairnes-enhanced federated learning scheme against label flipping attack[J].Journal of Information Security and Applications,2023,(77):103580,doi:10.1016/j.jisa.2023.103580.
[14] Zhou D W,Wang N N,Han B,et al.Modeling adversarial noise for adversarial training[C]//Proceedings of the 39th International Conference on Machine Learning(ICML),2022:27353-27366.
[15] Naseer M,Khan S,Hayat M,et al.A self-supervised approach for adversarial robustness[C]//Proceedings of IEEE Conference on Computer and Pattern Recognition(CVPR),2020:259-268.
[16] McMahan B,Moore E,Ramage D,et al.Communication-efficient learning of deep networks from decentralized data[C]//Artificial Intelligence and Statistics,Proceedings of Machine Learning Research(PMLR),2017:1273-1282.
[17] Fung,Clement,Yoon,et al.Thelimitations of federated learning in sybil settings[C]//23rd International Symposium on Research in Attacks,Intrusions and Defenses(RAID),2020:301-316.
[18] Cao Xiaoyu,Fang Minghong,Liu Jia,et al.FLTrust:Byzantine-robust federated learning via trust bootstrapping[C]//28th Annual Network and Distributed System Security Symposium(NDSS),2021,doi:10.48550/arXiv.2012.13995.
[19] Pillutla,Krishna,Kakade,et al.Robust aggregation for federated learning[J].IEEE Transactions on Signal Processing,2022,70:1142-1154,doi:10.1109/TSP.2022.3153135.
附中文参考文献:
[1] 钱文君,沈晴霓,吴鹏飞,等.大数据计算环境下的隐私保护技术研究进展[J].计算机学报,2022,45(4):669-701.
[4] 吴文泰,吴应良,林伟伟,等.横向联邦学习:研究现状、系统应用与挑战[J].计算机学报,2025,48(1):35-67.
[5] 高 莹,陈晓峰,张一余,等.联邦学习系统攻击与防御技术研究综述[J].计算机学报,2023,46(9):1781-1805.
[9] 马鑫迪,李清华,姜 琦,等.面向Non-IID数据的拜占庭鲁棒联邦学习[J].通信学报,2023,44(6):138-153.
[10] 吴立钊,汪晓丁,徐 恬,等. 面向半异步联邦学习的防御投毒攻击方法研究[J].信息网络安全,2024,24(10):1578-1585.

基金资助

国家自然科学基金项目(62061036,61841109)资助;内蒙古自然基金项目(2019MS06031)资助.

AI Summary AI Mindmap

0

访问

0

被引

详细

导航
相关文章

AI思维导图

/