《计算机应用》唯一官方网站

• •    下一篇

联邦学习中的安全威胁与防御措施综述

陈学斌,任志强,张宏扬   

  1. 华北理工大学
  • 收稿日期:2023-06-27 修回日期:2023-07-15 发布日期:2023-08-03 出版日期:2023-08-03
  • 通讯作者: 任志强
  • 基金资助:
    国家自然科学基金资助项目

Review on security threats and defense measures in federated learning

  • Received:2023-06-27 Revised:2023-07-15 Online:2023-08-03 Published:2023-08-03

摘要: 联邦学习是一种用于解决机器学习中数据共享问题和隐私保护问题的分布式学习方法,旨在多方共同训练一个机器学习模型并保护数据的隐私。但是,联邦学习本身存在安全威胁,这使得联邦学习在实际应用中面临巨大的挑战。因此,分析联邦学习面临的攻击和相应的防御措施对联邦学习的发展和应用至关重要。首先介绍了联邦学习的定义、流程和分类,联邦学习中的攻击者模型;然后,从联邦学习系统的鲁棒性和隐私性两方面介绍了可能遭受的攻击,并对不同攻击介绍了相应的防御措施,同时也指出防御方案的不足之处。最后,展望了安全的联邦学习系统。

关键词: 联邦学习, 隐私保护, 攻击与防御, 机器学习, 鲁棒性与隐私性

Abstract: Federated learning is a distributed learning approach for solving the data sharing problem and privacy protection problem in machine learning, aiming at multiple parties to jointly train a machine learning model and protect the privacy of data. However, there are security threats inherent in federated learning, which makes federated learning face great challenges in practical applications. Therefore, analyzing the attacks faced by federation learning and the corresponding defensive measures are crucial for the development and application of federation learning. First, the definition, process and classification of federated learning were introduced, and the attacker model in federated learning was introduced. Then, the possible attacks in terms of both robustness and privacy of federated learning systems were introduced, and the corresponding defense measures for different attacks were introduced as well. Furthermore, the shortcomings of the defense schemes were also pointed out. Finally, a secure federated learning system was envisioned.

Key words: federated learning, privacy protection, attack and defense, machine learning, Robustness and privacy

中图分类号: