Security analysis in federated learning based on adversarial attacks
Haonan Jiang · Applied and Computational Engineering · 2023
Federated learning can fully use more data to improve the model's performance, but there will be a significant risk once the communication data (such as gradient information) is exposed. The risk of communication data leakage is unacceptable to users. When an attacker gets a little communication data from somewhere, the leaked communication data is a deadly poison. Attackers only need this communication data to launch destructive attacks and quickly break through the defensive line. This paper studies how to defend this risk to improve the security of federated learning through simulated attack experiments. For example, a random pruning strategy compresses the attack model (deep neural network). The purpose is to change the model's structure without affecting the model's performance as much as possible to make the structure of the proxy model (attacker) and the attacked model different to verify whether the strategy can improve the defense capability of the model. The experimental results show that the gradient-based attack method has good generalization. Even if the structure of the neural network model is modified in this paper, it still cannot resist the specific attacks brought by gradient exposure.