Bayesian Optimisation-Driven Poisoning Attack Against Personalised Federated Learning in Metaverse

Marios Aristodemou, Xiaolan Liu, Sangarapillai Lambotharan · 2024

Metaverse is envisioned to be a human-centric framework that aims to provide a comprehensive and immersive experience for users in various domains, including education, medicine, and entertainment. As a large amount of private data is generated from each user, federated learning (FL) has emerged as an effective solution to ensure user privacy. Moreover, personalized FL (PFL) was further studied to increase the personalization of the trained model for each user. Nevertheless, the vulnerability of model aggregation to adversarial poisoning attacks still raises security concerns. To investigate the adversaries' behaviors, we propose an adversarial model poisoning attack that can evaluate the susceptibility of the PFL. This attack mechanism exploits layer optimization with Bayesian optimization to search for the optimal weights by optimizing two different objectives (i.e., mutual information and Kullback-Leibler divergence) for a hidden layer of the local model to induce classification uncertainty for the global model in PFL. Our numerical results indicate that the proposed attack method can successfully poison the PFL. Particularly, we show that our proposed attack mechanism affects the personalization of the local model and the applicability of using both optimization objectives to attack the PFL.

Read the paper · More papers on PaperTik