Peak-controlled logits poisoning attack in federated distillation
摘要
Federated Distillation (FD) is an innovative distributed machine learning paradigm that enables efficient and flexible cross-device knowledge transfer through knowledge distillation, without the need to upload large-scale model parameters to a central server. Although FD has attracted increasing attention in recent years, its security aspects remain relatively underexplored. Existing attack methods targeting traditional federated learning mainly focus on the transmission of model parameters and gradients, while attacks specifically designed for the unnormalized outputs (logits) in the emerging FD paradigm are still lacking. To fill this research gap and contribute to the enhancement of FD’s security, we previously proposed the Federated Distillation Logits Attack (FDLA), which manipulates the logits transmitted during communication to mislead and degrade the performance of client models. However, FDLA has limitations in controlling its impact on participants with different roles or identities and lacks a systematic investigation into the effects of malicious interventions at various stages of knowledge transfer. To overcome these limitations, we propose a more advanced and controllable logits poisoning method—Peak-Controlled Federated Distillation Logits Attack (PCFDLA). PCFDLA enhances the effectiveness of FDLA by precisely controlling the peak values of logits to adjust the intensity of the attack. This method generates highly misleading perturbations that achieve stronger attack performance while maintaining a similar level of stealthiness to FDLA when detection is based on differences in model parameters. Moreover, we introduce a novel evaluation metric to more comprehensively assess the performance of such attacks. Experimental results show that PCFDLA significantly increases the destructive impact on victim models while maintaining high stealth. It consistently achieves superior performance across multiple datasets, highlighting its potential threat to the security of federated distillation systems.