In this paper, we empirically analyze adversarial attacks on selected Federated Learning (FL) models. The specific models considered are FL versions of Multinominal Logistic Regression (MLR), Support Vector Classifier (SVC), Multilayer Perceptron (MLP), Convolution Neural Network (CNN), Random Forest, XGBoost, and Long Short-Term Memory (LSTM). For each model, we simulate label-flipping attacks, experimenting extensively with 10 federated clients and 100 federated clients. We vary the percentage of adversarial clients from 10 to 100% and, simultaneously, the percentage of labels flipped by each adversarial client is also varied from 10 to 100%. Among other results, we find that models differ in their inherent robustness to the two vectors in our label-flipping attack, i.e., the percentage of adversarial clients, and the percentage of labels flipped by each adversarial client. We discuss the potential practical implications of our results.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An Empirical Analysis of Federated Learning Models Subject to Label-Flipping Adversarial Attack

  • Kunal Bhatnagar,
  • Sagana Chattanathan,
  • Angela Dang,
  • Bhargav Eranki,
  • Ronnit Rana,
  • Charan Sridhar,
  • Siddharth Vedam,
  • Angie Yao,
  • Mark Stamp

摘要

In this paper, we empirically analyze adversarial attacks on selected Federated Learning (FL) models. The specific models considered are FL versions of Multinominal Logistic Regression (MLR), Support Vector Classifier (SVC), Multilayer Perceptron (MLP), Convolution Neural Network (CNN), Random Forest, XGBoost, and Long Short-Term Memory (LSTM). For each model, we simulate label-flipping attacks, experimenting extensively with 10 federated clients and 100 federated clients. We vary the percentage of adversarial clients from 10 to 100% and, simultaneously, the percentage of labels flipped by each adversarial client is also varied from 10 to 100%. Among other results, we find that models differ in their inherent robustness to the two vectors in our label-flipping attack, i.e., the percentage of adversarial clients, and the percentage of labels flipped by each adversarial client. We discuss the potential practical implications of our results.