联合学习的实际实施,用于在下一个词预测模型中检测后门攻击
Jimmy K W Wong1, Ki Ki Chung2, Yuen Wing Lo1
1Research and Development Office, The Education University of Hong Kong, Hong Kong, China.
Scientific reports
|January 17, 2025
概括
本研究介绍了一种方法来检测联合学习中的后门攻击,增强模型的安全性. 该方法有效地减轻了受损设备造成的偏差,确保更可靠的下一个词预测.
科学领域:
- 人工智能的人工智能
- 机器学习 机器学习
- 网络安全 网络安全
背景情况:
- 联合学习 (FL) 允许在分散的设备上进行协作模式培训,从而保护数据隐私.
- FL系统容易受到后门攻击,恶意参与者注入有偏见的数据来操纵模型输出.
- 这种攻击可以显著扭曲模型的性能,特别是在像选举这样的敏感话题上.
研究的目的:
- 开发和评估一种用于检测联合学习中的后门攻击的新机制.
- 通过联合学习培训的下一个词预测模型的稳定性和可靠性.
- 为了减轻恶意数据操纵对模型输出的影响.
主要方法:
- 开发一个联合学习框架,用于预测下一个词.
- 实施检测机制以识别和排除具有异常数据集的设备.
- 使用总统选举场景进行实验验证,以量化攻击影响和检测效率.
主要成果:
- 在受损设备的比例和模型偏差程度之间观察到正相关性.
- 拟议的检测机制有效地减少了后门攻击的影响,尤其是低比例的恶意设备.
- 该系统在针对目标数据中毒方面表现出了更好的稳定性.
结论:
- 开发的检测机制显著提高了联合学习系统的安全性和可靠性.
- 这项研究有助于在分散的环境中构建更可靠的AI模型.
- 这些发现强调了强有力的防御策略对抗对手操纵在联合学习的重要性.
相关概念视频
Prediction Intervals
2.2K
The interval estimate of any variable is known as the prediction interval. It helps decide if a point estimate is dependable.
However, the point estimate is most likely not the exact value of the population parameter, but close to it. After calculating point estimates, we construct interval estimates, called confidence intervals or prediction intervals. This prediction interval comprises a range of values unlike the point estimate and is a better predictor of the observed sample value, y.
However, the point estimate is most likely not the exact value of the population parameter, but close to it. After calculating point estimates, we construct interval estimates, called confidence intervals or prediction intervals. This prediction interval comprises a range of values unlike the point estimate and is a better predictor of the observed sample value, y.
2.2K
Improving Translational Accuracy
2.5K
2.5K
Associative Learning
286
Associative learning is a fundamental concept in behavioral psychology, wherein a connection is established between two stimuli or events, leading to a learned response. This process is critical in understanding how behaviors are acquired and modified. Conditioning, the mechanism through which associations are formed, can be divided into two main types: classical conditioning and operant conditioning, each elucidating different aspects of associative learning.
Classical conditioning, also known...
Classical conditioning, also known...
286
Force Classification
1.1K
Forces play a crucial role in the study of physics and engineering. They are essential in describing the motion, behavior, and equilibrium of objects in the physical world. Forces can be classified based on their origin, type, and direction of action.
Contact and non-contact forces are two of the most widely used categories of forces. As the name suggests, contact forces require physical contact between two objects to act upon each other. Examples of contact forces include frictional,...
Contact and non-contact forces are two of the most widely used categories of forces. As the name suggests, contact forces require physical contact between two objects to act upon each other. Examples of contact forces include frictional,...
1.1K
Wald-Wolfowitz Runs Test II
177
The Wald-Wolfowitz runs test, commonly referred to as the runs test, is a nonparametric test used to assess the randomness of ordered data. The test evaluates the number of runs, which are consecutive sequences of similar elements within the data. If the number of runs is significantly higher or lower than expected, the data is considered non-random, indicating a detectable pattern or structure.
For binary data, runs are identified using symbols such as + and −, or equivalently, 1s and...
For binary data, runs are identified using symbols such as + and −, or equivalently, 1s and...
177
Wald-Wolfowitz Runs Test I
604
The Wald-Wolfowitz test, also known as the runs test, is a nonparametric statistical test used to assess the randomness of a sequence of two different types of elements (e.g., positive/negative values, successes/failures). It examines whether the order of the elements in a sequence is random or if there is a pattern or trend present. This nonparametric test applies to any ordered data despite the population and sample data distribution, even if a higher sample size is available.
The test works...
The test works...
604


