Logo do repositório
 
Publicação

Data-Agnostic Model Poisoning against Federated Learning: A Graph Autoencoder Approach

dc.contributor.authorLi, Kai
dc.contributor.authorZheng, Jingjing
dc.contributor.authorYuan, Xin
dc.contributor.authorNi, Wei
dc.contributor.authorAkan, Ozgur B.
dc.contributor.authorPoor, H. Vincent
dc.date.accessioned2024-02-07T08:22:49Z
dc.date.available2024-02-07T08:22:49Z
dc.date.issued2024-02-01
dc.description.abstractThis paper proposes a novel, data-agnostic, model poisoning attack on Federated Learning (FL), by designing a new adversarial graph autoencoder (GAE)-based framework. The attack requires no knowledge of FL training data and achieves both effectiveness and undetectability. By listening to the benign local models and the global model, the attacker extracts the graph structural correlations among the benign local models and the training data features substantiating the models. The attacker then adversarially regenerates the graph structural correlations while maximizing the FL training loss, and subsequently generates malicious local models using the adversarial graph structure and the training data features of the benign ones. A new algorithm is designed to iteratively train the malicious local models using GAE and sub-gradient descent. The convergence of FL under attack is rigorously proved, with a considerably large optimality gap. Experiments show that the FL accuracy drops gradually under the proposed attack and existing defense mechanisms fail to detect it. The attack can give rise to an infection across all benign devices, making it a serious threat to FL.pt_PT
dc.description.versioninfo:eu-repo/semantics/publishedVersionpt_PT
dc.identifier.urihttp://hdl.handle.net/10400.22/24964
dc.language.isoengpt_PT
dc.titleData-Agnostic Model Poisoning against Federated Learning: A Graph Autoencoder Approachpt_PT
dc.title.alternative240201pt_PT
dc.typejournal article
dspace.entity.typePublication
rcaap.rightsopenAccesspt_PT
rcaap.typearticlept_PT

Ficheiros

Principais
A mostrar 1 - 1 de 1
A carregar...
Miniatura
Nome:
CISTER-TR-240201.pdf
Tamanho:
1.1 MB
Formato:
Adobe Portable Document Format
Licença
A mostrar 1 - 1 de 1
Miniatura indisponível
Nome:
license.txt
Tamanho:
1.71 KB
Formato:
Item-specific license agreed upon to submission
Descrição: