Self-adaptive federal learning model poisoning attack method based on gradient prediction
By using historical gradient changes and L-BFGS algorithm to predict global gradients in federated learning, combined with real-time poisoning feedback adaptively adjusting the perturbation factor of malicious gradients, the problem of low dependence and robustness of additional attack knowledge in the existing technology is solved, and stable concealment and attack intensity are achieved in different scenarios.
Patent Information
- Application Number
- CN202510102739.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-01-22
AI Technical Summary
The existing federated learning model poisoning attack methods rely on additional attack knowledge, and the attack is low in robustness, making it difficult to maintain stable concealment and attack strength under different defense strategies.
By using the L-BFGS algorithm to predict the current global gradient as the benchmark value of malicious perturbation based on the changing values of historical global gradients and global weights, the current global gradient is predicted as the reference value of malicious perturbation, and the perturbation factor of malicious gradients is adaptively adjusted through real-time poisoning feedback to optimize the concealment and attack intensity of malicious gradients.
A low-threshold model poisoning attack without additional knowledge is implemented. Malicious clients can maintain stable concealment and attack intensity under different data sets and defense strategies, reducing global model performance.
Smart Images

Figure CN120074876A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and particularly to an adaptive federated learning model poisoning attack method based on gradient prediction. Background Art
[0002] Federated learning is an emerging distributed machine learning paradigm that helps numerous clients collaborate to optimize a global model without sharing local sensitive data. Due to its privacy protection features, federated learning has gained wide popularity in both academia and industry, especially in fields such as medical image analysis, face recognition, and personalized recommendation systems. However, the invisibility of local data and the difficulty of verifying model gradients in its distributed aggregation make federated learning extremely vulnerable to model poisoning attacks. Malicious clients carefully craft malicious gradients similar to the benign gradient distribution and upload them, interfering with the aggregation of the global model through the perturbations added to the malicious gradients, causing the model to update in the wrong direction, thereby reducing the performance of the model and ultimately making incorrect decisions. Although model poisoning attacks have shown prominent attack impacts on classical federated learning algorithms such as FedAvg, with the proposal and update of robust aggregation defense strategies that can screen out malicious clients, how to ensure the concealment of model poisoning attacks under different defense strategies and improve the robustness of the model in different scenarios has become a major challenge in the research of model poisoning attacks.
[0003] Fang et al. proposed in their published paper "Local Model Poisoning Attacks to Byzantine-Robust Federated Learning (USENIX 2020)" that malicious clients use the benign gradients provided by colluding clients as the initial values of malicious perturbations and ensure the concealment of malicious gradients by adding adaptive perturbations. For different defense strategies, malicious clients perform aggregation simulations on local clients to test whether the malicious gradients after adding perturbations have sufficient concealment to escape the defense strategies. By continuously reducing the size of the perturbation factor to enhance the concealment of malicious gradients until it is ensured that all malicious gradients can escape the defense strategies and participate in model aggregation, and finally upload the malicious gradients with enhanced concealment to interfere with the global model aggregation. The disadvantages of this method are: on the one hand, both the local dataset and model gradients are precious data resources of clients and are protected in federated learning. At the same time, it is also unrealistic to collude with a specified number of colluding clients in large-scale federated learning; on the other hand, the specific malicious gradients designed for specific defense strategies are difficult to maintain stable concealment and attack intensity when facing defense strategies based on other mechanisms.
[0004] Shejwalkar et al. optimized the adaptive model poisoning attack proposed by Fang in their paper "Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning (NDSS2021)". First, the malicious client ensures the concealment of the malicious gradient by controlling the minimum distance between the malicious gradient and the benign gradient to be always less than the maximum distance between the benign gradients, weakening the limitation that the malicious gradient is only applicable to specific defense strategies, and at the same time enhancing the attack strength of the malicious gradient by finding the maximum perturbation factor that satisfies this concealment condition. The shortcomings of this method are: on the one hand, the method still does not get rid of the dependence on additional attack knowledge such as benign gradients and collusion clients; on the other hand, the method lacks actual poisoning feedback, does not evaluate the concealment and attack strength of malicious gradients in actual attack scenarios, and is difficult to improve and optimize malicious gradients in real-time environments. It is also difficult to ensure the effectiveness of the method when facing defense strategies of different mechanisms.
[0005] In summary, the existing model poisoning attack methods still have problems such as strong dependence on additional attack knowledge and low attack robustness in federated learning scenarios. Therefore, there is an urgent need for an adaptive federated model poisoning attack method that does not require additional knowledge, which can eliminate the attack's dependence on additional attack knowledge while ensuring that the attack is robust to different defense strategies in different scenarios, and ensure stable attack concealment and attack strength. Summary of the invention
[0006] In order to solve the above problems existing in the prior art, the present invention provides an adaptive federated learning model poisoning attack method based on gradient prediction, which specifically includes:
[0007] In a first aspect, the present invention provides an adaptive federated learning model poisoning attack method based on gradient prediction, comprising:
[0008] According to the historical global gradient and the historical global weight, the set of historical global gradient change values ΔG is obtained. (t) The set of historical global weight changes ΔW (t) ;
[0009] Using the historical global gradient change value set ΔG (t) The set of historical global weight changes ΔW (t) , and the global gradient g of the previous iteration (t-1) With the global weight w (t-1) , based on the L-BFGS algorithm, predict the global gradient of the current iteration round
[0010] Using the predicted global gradient as the baseline value of the malicious perturbation, adding a perturbation to the baseline value of the malicious perturbation to obtain the initial hidden malicious gradient and the initial sacrifice gradient;
[0011] Using the global gradient g obtained in the previous iteration round (t-1) , calculate the real-time poisoning feedback cs (t-1) ;
[0012] Based on the real-time poisoning feedback cs (t-1) , adaptively adjust the perturbation factor γ of the malicious gradient;
[0013] According to the updated perturbation factor γ of the malicious gradient, adjust the initial hidden malicious gradient and the initial sacrifice gradient to obtain the target hidden malicious gradient and the target sacrifice gradient and upload them to the central server to attack the federated learning model.
[0014] In a second aspect, the present invention also provides an electronic device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0015] The memory is used to store a computer program;
[0016] The processor is used to implement any method provided in the first aspect when executing the program stored on the memory.
[0017] In a third aspect, the present invention provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, any method provided in the first aspect is implemented.
[0018] In a fourth aspect, the present invention provides a program product, and the program product includes computer program instructions, and when the computer program instructions are executed, any method provided in the first aspect can be implemented.
[0019] Advantages of the present invention:
[0020] The adaptive federated learning model poisoning attack method based on gradient prediction provided by the present invention includes obtaining a set of change values ΔG of the historical global gradient (t) and a set of change values ΔW of the historical global weight (t) according to the historical global gradient and the historical global weight; using the set of change values ΔG of the historical global gradient (t) and the set of change values ΔW of the historical global weight (t) , as well as the global gradient g and the global weight w in the previous iteration round (t-1) in the previous iteration round(t-1) , based on the L-BFGS algorithm, predict the global gradient of the current iteration round Using the predicted global gradient as the benchmark value of the malicious perturbation, add perturbations to the benchmark value of the malicious perturbation to obtain the initial hidden malicious gradient and the initial sacrifice gradient; utilize the global gradient g obtained in the previous iteration round (t-1) to calculate the real-time poisoning feedback cs (t-1) ; based on the real-time poisoning feedback cs (t-1) , adaptively adjust the perturbation factor γ of the malicious gradient; according to the updated perturbation factor γ of the malicious gradient, adjust the initial hidden malicious gradient and the initial sacrifice gradient to obtain the target hidden malicious gradient and the target sacrifice gradient and upload them to the central server to attack the federated learning model. This method realizes a low-threshold model poisoning attack without additional knowledge. In the federated learning model poisoning method based on poisoning prediction provided by the present invention, the malicious client only needs to be able to receive the global gradient broadcast by the central server to create malicious gradients with sufficient concealment and attack intensity, without any accomplices. The malicious gradients are uploaded to the server through false clients to interfere with the global model aggregation and reduce the performance of the global model. At the same time, the present invention analyzes the attack concealment by calculating the deviation degree of the global gradient after being attacked towards the malicious gradient as the real-time poisoning feedback, and adaptively adjusts the size of the malicious perturbation factor based on this. Without additional knowledge, the malicious gradients can be optimized, ensuring that the attack has stable concealment and attack intensity in diverse federated scenarios such as different data sets and different defense strategies.
[0021] The following will further elaborate on the present invention in conjunction with the drawings and embodiments. Description of the Drawings
[0022] Figure 1 is a schematic flowchart of the adaptive federated learning model poisoning attack method based on gradient prediction provided by the present invention. Specific Embodiments
[0023] The following further describes the present invention in detail with specific embodiments, but the implementation manners of the present invention are not limited thereto.
[0024] In federated learning, malicious clients take advantage of the invisibility of local data and the difficulty of verifying model gradients to upload carefully crafted malicious gradients to conduct model poisoning attacks on the federated global model. To counter robust federated aggregation defense strategies that can screen out malicious clients, malicious clients improve the concealment of model poisoning attacks by narrowing the distribution distance between malicious gradients and benign gradients, thereby evading the detection of defense strategies. However, the privacy of local data and model gradients of benign clients, the differences in data under different scenarios, and the diversity of defense strategies make it a challenge to ensure the concealment and enhance the robustness of model poisoning attacks in practical application scenarios. The existing technologies have the following disadvantages: (1) The existing technologies rely on additional attack knowledge assumptions such as local datasets, benign gradients, and a certain number of colluding clients, and are less feasible in federated learning where private data is protected; (2) The existing technologies lack real-time poisoning feedback for malicious gradients, making it difficult to ensure sufficient concealment under different datasets and different defense strategies, achieve a stable attack effect, and have poor robustness.
[0025] To address the above disadvantages, the present invention constructively designs an adaptive federated learning model poisoning attack method based on gradient prediction. By predicting the global gradient and optimizing the adaptive malicious gradient perturbation based on poisoning feedback, the attack threshold is reduced and the robustness of the model poisoning attack is enhanced. Compared with existing methods, on the one hand, the present invention predicts the latest global gradient based on historical global gradients and uses it as a fitting estimate of the benign gradient. By approximating the benign gradient by predicting the current global gradient with historical global gradients, the attack prerequisite knowledge assumptions about local datasets and local model gradients in model poisoning attacks are eliminated, and the additional dependencies on colluding clients and client private data in the attack are removed. It can determine the benchmark direction of malicious gradients without additional knowledge, ensuring the initial concealment of malicious gradients; on the other hand, the present invention calculates the deviation degree of the global gradient after poisoning from the malicious gradient as poisoning feedback, evaluates the real-time concealment of malicious gradients, and adaptively adjusts the perturbation factor of malicious gradients based on this to enhance the concealment or stimulate the attack of malicious gradients, enabling malicious gradients to have specific real-time optimizations for different defense strategies on different datasets, enhancing the robustness of the model poisoning attack, and ensuring the concealment and stable attack intensity of model poisoning attacks in different scenarios.
[0026] The present invention can be applied to scenarios such as intelligent mobile devices, finance, healthcare, and advertising recommendation systems. It designs a framework for evaluating the security of a federated learning system under model poisoning attacks, providing researchers with a systematic method to analyze attack threats and verify the effectiveness of defense mechanisms. For example, in the financial field, due to the need for privacy protection, customer asset data cannot be shared. To analyze a user's loan repayment ability and borrowing credit, different banks or financial institutions, as clients, can locally use customer asset data (such as deposits, real estate), customer historical consumption records, historical credit scores, etc. to train local models, and then upload the local model gradients to the central server. Malicious clients pose as false institutions and upload carefully crafted malicious gradients. The central server aggregates the model gradients uploaded by each financial institution to obtain the global gradient, and then sends the global gradient to different financial institutions for iterative training. Affected by the malicious gradients, the global gradient is updated in the wrong direction, and the global model will ultimately make incorrect decisions. Since the present invention does not require additional attack knowledge such as local datasets and colluding clients, it can launch attacks solely as a federated participant with the help of false clients, reducing the attack threshold in practical application scenarios. Before the formal training and deployment of the federated model, the present invention can be used to evaluate and select the robust aggregation defense strategy of the central server, and select the defense strategy with the strongest detection ability and highest attack resistance according to the attack success rate of the present invention. The present invention aims to promote the update and improvement of defense strategies by verifying the effectiveness of defense strategies.
[0027] Figure 1 FIG. is a schematic flowchart of an adaptive federated learning model poisoning attack method based on gradient prediction provided by the present invention. This method can be used in the simulation process of poisoning attacks on federated learning models, specifically for simulating malicious clients.
[0028] As Figure 1 shown, the method includes:
[0029] S101. Obtain a set of change values of historical global gradients and a set of change values of historical global weights according to historical global gradients and historical global weights.
[0030] Specifically: according to historical global gradients and historical global weights, obtain a set of change values ΔG (t) of historical global gradients and a set of change values ΔW (t) of historical global weights.
[0031] In a possible implementation manner, obtaining a set of change values ΔG (t) of historical global gradients and a set of change values ΔW (t) of historical global weights according to historical global gradients and historical global weights includes: receiving the global gradient g (t), and update the model weights w (t) ; Calculate the change values of the global gradient and global weights from the (t - 2)-th round to the (t - 1)-th round respectively, and store them in the set ΔG of the change values of the historical global gradient (t) and the set ΔW of the change values of the historical global weights (t) respectively, which is expressed as:
[0032] ΔG (t) : {Δg (t-N) …Δg (t-1)},
[0033] ΔW (t) : {Δw (t-N) …Δw (t-1)},
[0034] where Δg (t-1) represents the change value from the global gradient g (t-2) in the (t - 2)-th round to the global gradient g (t-1) in the (t - 1)-th round, and Δw (t-1) represents the change value from the global weight w (t-2) in the (t - 2)-th round to the global weight w (t-1) in the (t - 1)-th round. The lengths of the set of the change values of the historical global gradient and the set of the change values of the historical global weights are both N.
[0035] S102. Use the set of the change values of the historical global gradient and the set of the change values of the historical global weights, as well as the global gradient and global weights of the previous iteration round, to predict the global gradient of the current iteration round based on the L - BFGS algorithm.
[0036] Specifically: Use the set ΔG of the change values of the historical global gradient (t) and the set ΔW of the change values of the historical global weights (t) , as well as the global gradient g (t-1) and the global weight w (t-1) of the previous iteration round, to predict the global gradient
[0037] In a possible implementation manner, use the set ΔG of the change values of the historical global gradient (t) and the set ΔW of the change values of the historical global weights (t) , as well as the global gradient g (t-1) and the global weight w (t-1) of the previous iteration round, to predict the global gradient which is expressed as:
[0038] W W =ΔW (t)T·ΔW (t) ,W G =ΔW (t)T ·ΔG (t) ,
[0039] L(W G )=W G -U(W G ),
[0040] ξ=Δg (t-1)T Δw (t-1) / Δw (t-1)T Δw (t-1) ,
[0041]
[0042]
[0043] Among them, U(G) represents the upper triangular matrix of W G , D(·) represents taking the diagonal matrix, D(D(W G )) represents the diagonal matrix of W G , the superscript T represents the transpose, represents the change value of the global gradient in the current iteration round.
[0044] Based on the L-BFGS algorithm, the present invention uses the broadcast historical global gradient to predict the global gradient of subsequent iterations in advance, and locates the benchmark malicious gradient based on this to ensure the initial concealment of the attack.
[0045] S103. Use the predicted global gradient as the benchmark value of the malicious perturbation, and add a perturbation to the benchmark value of the malicious perturbation to obtain the initial concealed malicious gradient and the initial sacrifice gradient.
[0046] Specifically: Use the predicted global gradient as the benchmark value of the malicious perturbation, and add a perturbation to the benchmark value of the malicious perturbation to obtain the initial concealed malicious gradient and the initial sacrifice gradient.
[0047] In a possible implementation manner, use the predicted global gradient as the benchmark value of the malicious perturbation, and add a perturbation to the benchmark value of the malicious perturbation to obtain the initial concealed malicious gradient and the initial sacrifice gradient, which is expressed as:
[0048]
[0049]
[0050]
[0051]
[0052] Among them, represents the perturbation unit vector, ||·|| represents the two-norm of the vector, Δp represents the benchmark value of the malicious perturbation, and {j 1 , j 2 … j c} represents the predicted global gradient in the top c absolute values corresponding to the dimensions sorted from largest to smallest in each dimension of, where j represents the predicted global gradient the index of the dimension in represents the initial hidden malicious gradient, γ represents the perturbation factor of the malicious gradient, represents the initial sacrifice gradient, and K represents the perturbation amplification factor of the sacrifice gradient.
[0053] Specifically, calculate the change value of the predicted global gradient and use the unit vector as the perturbation unit vector Sort the absolute values of each dimension in the predicted global gradient and record the top c dimensions with the largest values, denoted as {j 1 , j 2 … j c}, retain the values corresponding to {j 1 , j 2 … j c} dimensions, and set the values of the remaining dimensions to 0 as the final basic perturbation Δp, that is, the benchmark value of the malicious perturbation.
[0054] It should be noted that dimensions with larger absolute values mean that they have a greater impact on the objective optimization of the model task and are more likely to change the output under small perturbations. Therefore, the present invention adds perturbations to dimensions with larger absolute values to minimize the distribution difference between the malicious gradient and the benign gradient while maximizing the impact of the attack on the global model.
[0055] Furthermore, determine the initial hidden malicious gradient according to , where γ is the perturbation factor of the malicious gradient, which is initially set by the malicious client and then gradually optimized through adaptive adjustment during the attack process. When γ is smaller, the concealment of the malicious gradient is stronger, but the attack effect is weak. On the contrary, the concealment of the malicious gradient is weakened but the attack effect is enhanced. In order to ensure that the malicious gradient has sufficient distribution difference while having a distribution similarity with the benign gradient, an extra-large perturbation is added to the benchmark value and the sacrifice gradient is made reversely
[0056] S104. Use the global gradient obtained in the previous iteration round to calculate the real-time poisoning feedback.
[0057] Specifically: using the globally obtained gradient g of the previous iteration (t-1) , calculate the real-time poisoning feedback cs (t-1) .
[0058] In a possible implementation, using the globally obtained gradient g of the previous iteration (t-1) , calculate the real-time poisoning feedback cs (t-1) , including: using the cosine similarity as the calculation metric for the poisoning feedback, calculating the cosine similarity between the globally obtained gradient g of the previous iteration (t-1) and the mean of the malicious gradients used for attack in the previous iteration , and determining the cosine similarity as the poisoning feedback cs (t-1) , expressed as:
[0059]
[0060] Since the attack target is to make the globally obtained gradient deviate in the direction of the malicious gradient, so that the model is updated incorrectly, the larger the value of the poisoning feedback cs (t-1) obtained by using the above method, the higher the degree of deviation of the globally obtained gradient in the direction of the malicious gradient.
[0061] This method analyzes the concealment of the attack by calculating the real-time poisoning feedback, analyzes the degree of deviation of the globally obtained gradient after being attacked in the direction of the malicious gradient by calculating the cosine similarity between the globally obtained gradient after being attacked and the mean of the corresponding malicious gradients used for attack, and judges whether the attack maintains the concealment of the escape defense strategy detection according to the comparison between the real-time poisoning feedback and the lowest threshold of the expected feedback.
[0062] S105. Based on the real-time poisoning feedback, adaptively adjust the perturbation factor of the malicious gradient.
[0063] Specifically: based on the real-time poisoning feedback cs( t-1 ), adaptively adjust the perturbation factor γ of the malicious gradient.
[0064] Since in diverse federated scenarios such as different datasets and different defense strategies, the concealment and attack intensity of the malicious gradient change with the change of the gradient of the client local model, it may lead to the disappearance of the concealment of the malicious gradient or the weakness of the attack intensity, resulting in the failure of the attack. Therefore, the present invention designs an adaptive adjustment mechanism for the perturbation of the malicious gradient based on the real-time poisoning feedback, so that the malicious gradient can maintain stable concealment and attack intensity in a changing scenario. It analyzes the real-time attack feedback, adaptively adjusts the magnitude of the malicious perturbation factor, thereby adjusting the perturbation amplitude of the malicious gradient, so that the malicious gradient has sufficient concealment while increasing the attack impact.
[0065] In a possible implementation, based on the real-time poisoning feedback cs(t-1) Adaptive adjustment is performed on the perturbation factor γ of the malicious gradient, including: when the real-time poisoning feedback cs (t-1) is lower than the preset minimum poisoning feedback threshold CS min , the value of the perturbation factor γ of the malicious gradient is decreased; when the real-time poisoning feedback cs (t-1) is higher than the preset minimum poisoning feedback threshold CS min , the value of the perturbation factor γ of the malicious gradient is increased.
[0066] Specifically, initially, the malicious client sets the minimum poisoning feedback threshold CS min , and by comparing the real-time poisoning feedback cs (t-1) with the minimum poisoning feedback threshold CS min , the following analysis and adjustment are performed on the concealment and attack strength of the perturbation factor γ of the malicious gradient:
[0067] 1) Concealment enhancement: When the real-time poisoning feedback cs (t-1) is lower than the expected threshold CS min , it indicates that the concealment of the malicious gradient is insufficient and fails to escape the detection of the defense mechanism. Therefore, to improve the concealment of the malicious gradient, the value of the perturbation factor γ of the malicious gradient is decreased, thereby reducing the perturbation amplitude of the gradient and making the malicious gradient closer to the benign gradient.
[0068] 2) Attack incentive: When the feedback cs (t-1) exceeds the expected threshold CS min , it indicates that the global gradient has successfully moved in the direction of the desired malicious gradient, and the malicious gradient is in a concealed state and not detected by the defense strategy. At this time, the value of the perturbation factor γ is increased to further amplify the perturbation amplitude. Make the malicious gradient enhance the attack impact while maintaining concealment.
[0069] Optionally, it further includes: setting the lower limit γ min and the upper limit γ max corresponding to the perturbation factor γ of the malicious gradient; correspondingly, when adaptively adjusting the perturbation factor γ of the malicious gradient based on the real-time poisoning feedback cs( t-1 ), always control the perturbation factor γ of the malicious gradient to vary between the lower limit γ min and the upper limit γ max .
[0070] Specifically, for the perturbation factor γ of the malicious gradient, two limits need to be established, namely the lower limit γ min and the upper limit γ max . The lower limit γ min can prevent the perturbation from becoming too small, thereby ensuring that the malicious gradient does not have a weak attack impact on the global model due to being too close to the benign gradient. At the same time, to prevent triggering the defense mechanism, an upper limit γ is established.max , to ensure that during the adjustment of the perturbation factor γ of the malicious gradient, the perturbation will not exceed the threshold due to excessive attack incentives, thus damaging the concealment of the malicious gradient.
[0071] S106. Adjust the initial concealed malicious gradient and the initial sacrifice gradient according to the updated perturbation factor of the malicious gradient, obtain the target concealed malicious gradient and the target sacrifice gradient, and upload them to the central server to attack the federated learning model.
[0072] Specifically: Adjust the initial concealed malicious gradient and the initial sacrifice gradient according to the updated perturbation factor γ of the malicious gradient to obtain the target concealed malicious gradient and the target sacrifice gradient and upload them to the central server to attack the federated learning model.
[0073] It should be particularly noted that since the present invention does not require any additional federated privacy knowledge and conspirators, the present invention receives the global gradient and uploads the malicious model gradient by creating malicious clients (such as Sybil attacks, Android emulators, etc.). Assuming the number of malicious clients is m, the malicious clients upload a total of (m - 1) concealed gradients and one sacrifice gradient.
[0074] The method for poisoning attack on the adaptive federated learning model based on gradient prediction provided by the present invention includes obtaining the set ΔG of change values of the historical global gradient (t) and the set ΔW of change values of the historical global weight (t) ; using the set ΔG of change values of the historical global gradient (t) and the set ΔW of change values of the historical global weight (t) , as well as the global gradient g (t-1) and the global weight w (t-1) of the previous iteration round, based on the L - BFGS algorithm, predict the global gradient of the current iteration round Taking the predicted global gradient as the benchmark value of the malicious perturbation, add perturbations to the benchmark value of the malicious perturbation to obtain the initial concealed malicious gradient and the initial sacrifice gradient; use the obtained global gradient g( t-1 ) of the previous iteration round to calculate the real - time poisoning feedback cs( t-1 ); based on the real - time poisoning feedback cs( t-1 ), adaptively adjust the perturbation factor γ of the malicious gradient; according to the updated perturbation factor γ of the malicious gradient, adjust the initial concealed malicious gradient and the initial sacrifice gradient to obtain the target concealed malicious gradient and the target sacrifice gradient And upload it to the central server to attack the federated learning model. This method realizes a low-threshold model poisoning attack without additional knowledge. In the federated learning model poisoning method based on poisoning prediction provided by the present invention, a malicious client only needs to be able to receive the global gradient broadcast by the central server to produce malicious gradients with sufficient concealment and attack intensity. Without any accomplices, the malicious gradients are uploaded to the server through false clients to interfere with the global model aggregation and reduce the performance of the global model. At the same time, the present invention calculates the deviation degree of the global gradient after being attacked towards the malicious gradient as real-time poisoning feedback to analyze the attack concealment, and adaptively adjusts the size of the malicious perturbation factor based on this, optimizing the malicious gradients without additional knowledge, ensuring that the attack has stable concealment and attack intensity in diverse federated scenarios such as different datasets and different defense strategies.
[0075] The present invention also provides a structure of an electronic device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus.
[0076] The memory is used to store computer programs.
[0077] When the processor is used to execute the programs stored on the memory, it realizes the steps provided in the above method embodiments.
[0078] The communication interface is used for communication between the above electronic device and other devices.
[0079] The method provided by the embodiments of the present invention can be applied to electronic devices. Specifically, the electronic device can be: a desktop computer, a portable computer, a smart mobile terminal, a server, etc. There is no limitation here. Any electronic device that can implement the present invention belongs to the protection scope of the present invention.
[0080] The present invention also provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, it realizes the steps provided in the above method embodiments.
[0081] The present invention also provides a program product. The program product includes program instructions. When the program instructions are executed by a processor, they realize the steps provided in the above method embodiments.
[0082] For the embodiments of the electronic device / storage medium / program product, since they are basically similar to the method embodiments, the description is relatively simple. For the specific content and beneficial effects, etc., refer to the partial description of the method embodiments.
[0083] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality of" means two or more unless otherwise specifically defined.
[0084] The above content is a further detailed description of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is limited only to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as falling within the protection scope of the present invention.
Claims
1. An adaptive federated learning model poisoning attack method based on gradient prediction, characterized in that: include: According to the historical global gradient and the historical global weight, the set of historical global gradient change values ΔG is obtained. (t) The set of historical global weight changes ΔW (t) ; Using the historical global gradient change value set ΔG (t) The set of historical global weight changes ΔW (t) , and the global gradient g of the previous iteration (t-1) With the global weight w (t-1) , based on the L-BFGS algorithm, predict the global gradient of the current iteration round Take the predicted global gradient As a base value of malicious disturbance, adding disturbance to the base value of malicious disturbance to obtain an initial hidden malicious gradient and an initial sacrificial gradient; Using the global gradient g obtained from the previous iteration (t-1) , calculate the real-time poisoning feedback cs (t-1) ; Based on the real-time poisoning feedback cs (t-1) , adaptively adjust the disturbance factor γ of the malicious gradient; According to the disturbance factor γ of the updated malicious gradient, the initial hidden malicious gradient and the initial sacrifice gradient are adjusted to obtain the target hidden malicious gradient Sacrificing gradient with target And upload it to the central server to attack the federated learning model.
2. The method according to claim 1, characterized in that: According to the historical global gradient and the historical global weight, the set of historical global gradient change values ΔG is obtained. (t) The set of historical global weight changes ΔW (t) ,include: Receive the global gradient g sent by the central server (t) , and update the model weight w (t) ; Calculate the change values of the global gradient and global weight from the t-2th round to the t-1th round, and store them in the historical global gradient change value set ΔG (t) , the set of historical global weight change values ΔW (t) In, it is expressed as: ΔG (t) :{Δg (t-N) …Δg (t-1) }, ΔW (t) :{Δw (t-N) …Δw (t-1) }, Where, Δg (t-1) Represents the global gradient g from the t-2th round (t-2) The global gradient g to the t-1th round (t-1) The change in value, Δw (t-1) Represents the global weight w from the t-2th round (t-2) The global weight w at round t-1 (t-1) The length of the historical global gradient change value set and the historical global weight change value set are both N.
3. The method according to claim 2, characterized in that Using the historical global gradient change value set ΔG (t) The set of historical global weight changes ΔW (t) , and the global gradient g of the previous iteration (t-1) With the global weight w (t-1) , based on the L-BFGS algorithm, predict the global gradient of the current iteration round It is expressed as: IN W =ΔW (t)T ·ΔW (t) ,IN G =ΔW (t)T ΔG (t) , L(W G )=W G -U(W G ), ξ=Δg (t-1)T Δw (t-1) / Δw (t-1)T Δw (t-1) , Where U(G) represents W G The upper triangular matrix of D(·) represents the diagonal matrix, D(D(W G )) indicates W G The diagonal matrix of , the superscript T indicates the transpose, Indicates the change in the global gradient of the current iteration.
4. The method according to claim 3, characterized in that Take the predicted global gradient As the benchmark value of malicious disturbance, the disturbance is added to the benchmark value of malicious disturbance to obtain the initial hidden malicious gradient and the initial sacrificial gradient, which are expressed as: in, represents the disturbance unit vector, ||·|| represents the second norm of the vector, Δp represents the baseline value of the malicious disturbance, {j1,j2…j c } represents the global gradient of the prediction The absolute values of each dimension in the descending order correspond to the dimensions of the first c absolute values, and j represents the predicted global gradient The index of the medium dimension, represents the initial hidden malicious gradient, γ represents the perturbation factor of the malicious gradient, represents the initial sacrificed gradient, and K represents the perturbation amplification factor of the sacrificed gradient.
5. The method according to claim 4, characterized in that Using the global gradient g obtained from the previous iteration (t-1) , calculate the real-time poisoning feedback cs (t-1) ,include: Use cosine similarity as the calculation indicator for poisoning feedback and calculate the global gradient g of the previous iteration round (t-1) The mean of the malicious gradients of the previous iteration round and determine the cosine similarity as the poisoning feedback cs (t-1) , expressed as:
6. The method according to claim 5, characterized in that Based on the real-time poisoning feedback cs (t-1) , adaptively adjusting the disturbance factor γ of the malicious gradient, including: When real-time poisoning feedback cs (t-1) Lower than the preset minimum threshold CS for poisoning feedback min , reducing the value of the disturbance factor γ of the malicious gradient; When real-time poisoning feedback cs (t-1) Higher than the preset minimum threshold CS for poisoning feedback min , increase the value of the disturbance factor γ of the malicious gradient.
7. The method according to claim 6, characterized in that Also includes: Set the lower limit γ corresponding to the perturbation factor γ of the malicious gradient min and the upper limit γ max ; Accordingly, based on the real-time poisoning feedback cs (t-1) , when the disturbance factor γ of the malicious gradient is adaptively adjusted, the disturbance factor γ of the malicious gradient is always controlled within the lower limit γ min and the upper limit γ max Changes between.
8. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing any of the methods described in claims 1-7 when executing a program stored in a memory.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
10. A program product, characterized in that The program product comprises computer program instructions, and when the computer program instructions are executed, the method according to any one of claims 1 to 7 can be implemented.
Citation Information
Patent Citations
Differential privacy federal learning method based on random election verification block chain
CN117077806A
Two-dimensional poisoning attack defense method in federal learning
CN117494123A
Robustness federated learning method capable of resisting backdoor attack based on joint defense
CN118297178A
Poison attack method for disturbing federal recommendation system common model
CN118427814A
Generative adversarial-based attack in federated learning
WO2023012230A2