A First Order Meta Stackelberg Method for Robust Federated Learning (Technical Report)
Fuente:
arXiv
Enregistré dans:
| Auteurs principaux: | , , , , , |
|---|---|
| Format: | Preprint |
| Publié: |
2023
|
| Sujets: | |
| Accès en ligne: | |
| Tags: |
Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
|
| _version_ | 1866908718810005504 |
|---|---|
| author | Li, Henger Xu, Tianyi Li, Tao Pan, Yunian Zhu, Quanyan Zheng, Zizhan |
| author_facet | Li, Henger Xu, Tianyi Li, Tao Pan, Yunian Zhu, Quanyan Zheng, Zizhan |
| contents | Recent research efforts indicate that federated learning (FL) systems are vulnerable to a variety of security breaches. While numerous defense strategies have been suggested, they are mainly designed to counter specific attack patterns and lack adaptability, rendering them less effective when facing uncertain or adaptive threats. This work models adversarial FL as a Bayesian Stackelberg Markov game (BSMG) between the defender and the attacker to address the lack of adaptability to uncertain adaptive attacks. We further devise an effective meta-learning technique to solve for the Stackelberg equilibrium, leading to a resilient and adaptable defense. The experiment results suggest that our meta-Stackelberg learning approach excels in combating intense model poisoning and backdoor attacks of indeterminate types. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2306_13273 |
| institution | arXiv |
| publishDate | 2023 |
| record_format | arxiv |
| spellingShingle | A First Order Meta Stackelberg Method for Robust Federated Learning (Technical Report) Li, Henger Xu, Tianyi Li, Tao Pan, Yunian Zhu, Quanyan Zheng, Zizhan Cryptography and Security Computer Science and Game Theory Recent research efforts indicate that federated learning (FL) systems are vulnerable to a variety of security breaches. While numerous defense strategies have been suggested, they are mainly designed to counter specific attack patterns and lack adaptability, rendering them less effective when facing uncertain or adaptive threats. This work models adversarial FL as a Bayesian Stackelberg Markov game (BSMG) between the defender and the attacker to address the lack of adaptability to uncertain adaptive attacks. We further devise an effective meta-learning technique to solve for the Stackelberg equilibrium, leading to a resilient and adaptable defense. The experiment results suggest that our meta-Stackelberg learning approach excels in combating intense model poisoning and backdoor attacks of indeterminate types. |
| title | A First Order Meta Stackelberg Method for Robust Federated Learning (Technical Report) |
| topic | Cryptography and Security Computer Science and Game Theory |
| url | https://arxiv.org/abs/2306.13273 |