Information-Agnostic Model Poisoning Attacks Against Byzantine-Robust Federated Learning
摘要
Federated learning (FL), as a popular distributed machine learning paradigm in various applications, is faced with Byzantine failure caused by malicious clients. To overcome this issue, Byzantine-robust FL uses robust aggregation algorithm (AGR) to defend against adversaries. Current attacks often assume prior knowledge of the AGR and benign updates, which is impractical. In this paper, we propose a novel information-agnostic model poisoning attack named GGO to break down prevailing robust AGRs. With GGO, the attackers require no knowledge of the central server or the benign clients, and need only manipulate local updates of controlled clients. The GGO attack is designed based on the scheme of gap-based group obfuscating to manipulate the local updates in a fine-grained manner. We provide theoretical guarantee of the effectiveness of GGO towards representative state-of-the-art robust AGR method Zeno. Extensive experimental results further show that GGO attack can defeat five widely-used defence methods, Zeno, Krum, Trimmed Mean, Median and Centered Clipping. Specifically, on the CIFAR-10 dataset with 27 clients, our attack achieves an average drop in accuracy of 47.7%.