兼顾高效与安全的松耦合跨域协作学习平台
收稿日期: 2023-11-07
网络出版日期: 2025-01-25
基金资助
国家自然科学基金(62202258,62425201,62132011,U22B2031)
版权
Loose coupling cross-domain collaborative learning platform with both efficiency and security
Received date: 2023-11-07
Online published: 2025-01-25
Copyright
协作学习受制于苛刻的通信与部署条件,无法实现高效部署。此外,协作学习面临对抗攻击和隐私泄露等安全威胁。为了促进协作学习在现实世界的部署应用,设计并实现了兼顾高效和安全的松耦合跨域协作学习平台。采用松耦合设计模式,高效并安全地实现协作学习。同时,采用云—边—端协同的三层架构,针对训练任务的合法性与隔离性进行了系统安全设计,从而在系统层面上同时兼顾高效性与安全性。相比于集中式人工智能方案,基于本平台实现的协作学习,在黑产商家识别和恶意流量检测2个任务上,预测性能分别提升 35.29% 和 8.30%。在抵御对抗攻击方面,部署对抗训练模块前后,模型鲁棒性在两个任务上分别提升了570% 和 290%。在抵御成员推理攻击方面, 部署差分隐私模块前后,攻击成功率降低了 26.33%。
苏家兴 , 赵乙 , 李奥 , 谭崎 , 刘自轩 , 松永健宏 , 徐恪 . 兼顾高效与安全的松耦合跨域协作学习平台[J]. 网络空间安全科学学报, 2024 , 2(6) : 74 -85 . DOI: 10.20172/j.issn.2097-3136.240605
Collaborative learning faces challenges in the real-world deployment due to the stringent communication and deployment condi- tions, as well as security threats like adversarial attacks and privacy breaches. To facilitate the practical application of collaborative learning, a loose coupling cross-domain collaborative learning platform that balances efficiency and security was designed and implemented. Specifically, a loosely coupled design pattern was employed to achieve the collaborative learning with efficiency and security. A three-tier architecture encompassing cloud, edge, and endpoint collaboration was adopted, addressing the system’s security with regard to the training task legitimacy and isolation, and simultaneously ensuring efficiency and security at the system level. Compared the to centralized artificial intelligence solutions, collaborative learning implemented on this platform exhibited performance improvements of 35.29% and 8.30% in tasks involving the underground business recognition and the malicious traffic detection, respectively. In terms of the defense against adversarial attacks, the model's robustness increased by 570% and 290% in the two tasks after deploying an adversarial training module. Furthermore, the success rate of member inference attacks decreased by 26.33% after deploying a differential privacy module.
表 1 数据隐私性对比实验结果Table 1 Comparison of data privacy in underground business recognition tasks |
| 无差分隐私 | ε=10, δ=1e-5 | ε=10, δ=1e-6 | |
| 模型NDCG | 0.618 | 0.553 | 0.547 |
| 攻击精度 | 0.736 | 0.553 | 0.542 |
| 攻击AUC | 0.802 | 0.589 | 0.57 |
| 攻击F1-Score | 0.773 | 0.623 | 0.308 |
①
| 1 |
BROWN T, MANN B, RYDER N, et al. Language models are few-shot learners[J]. Advances in Neural Information Processing Systems, 2020, 33, 1877- 1901.
|
| 2 |
MCMAHAN B,MOORE E,RAMAGE D,et al. Communication- efficient learning of deep networks from decentralized data[C]//Proceedings of International Conference on Artificial Intelligence and Statistics (AISTATS). PMLR,2017:1273-1282.
|
| 3 |
ZHAO Y, XU K, CHEN J, et al. Collaboration-enabled intelligent internet architecture: opportunities and challenges[J]. IEEE Network, 2022, 36 (5): 98- 105.
|
| 4 |
SHARAFALDIN I,LASHKARI AH,HAKAK S,et al. Developing realistic distributed denial of service (DDoS) attack dataset and taxonomy[C]//2019 international carnahan conference on security technology (ICCST). IEEE,2019: 1-8.
|
| 5 |
WEI K, LI J, MA C, et al. Vertical federated learning: challenges, methodologies and experiments[J]. ArXiv preprint ArXiv:, 2202, 04309, 2022.
|
| 6 |
LIU Y, KANG Y, XING C, et al. A secure federated transfer learning framework[J]. IEEE Intelligent Systems, 2020, 35 (4): 70- 82.
|
| 7 |
LIU Y,KANG Y,XING C,et al. A secure federated transfer learning framework[J]. IEEE Intelligent Systems,2020,35(4):70-82.
|
| 8 |
WARNAT-HERRESTHAL S, SCHULTZE H, SHASTRY K L, et al. Swarm learning for decentralized and confidential clinical machine learning[J]. Nature, 2021, 594 (7862): 265- 270.
|
| 9 |
LI T, SAHU A K, ZAHEER M, et al. Federated optimization in heterogeneous networks[J]. Proceedings of Machine Learning and Systems,2020, 2:429-450.
|
| 10 |
KARIMIREDDY S P,KALE S,MOHRI M,et al. Scaffold:stochastic controlled averaging for federated learning[C]//International Conference on Machine Learning. PMLR,2020:5132-5143.
|
| 11 |
ZHOU G,LI Q,LIU Y,et al. edPAGE:pruning adaptively toward global efficiency of heterogeneous federated learning[J]. IEEE/ACM Transactions on Networking, 2024, 32(3):1873-1887.
|
| 12 |
WANG J, LIU Q, LIANG H, et al. Tackling the objective inconsistency problem in heterogeneous federated optimization[J]. Advances in Neural Information Processing Systems, 2020, 33, 7611- 7623.
|
| 13 |
GEYER R C, KLEIN T, NABI M. Differentially private federated learning: a client level perspective[J]. ArXiv preprint ArXiv:, 1712, 07557, 2017.
|
| 14 |
WEI K,LI J,DING M,et al. Federated learning with differential privacy:algorithms and performance analysis[J]. IEEE Transactions on Information Forensics and Security,2020,15:3454-3469.
|
| 15 |
TRUEX S,LIU L,CHOW K H,et al. LDP-Fed:federated learning with local differential privacy[C]//Proceedings of the Third ACM Inter- national Workshop on Edge Systems,Analytics and Networking. 2020:61-66.
|
| 16 |
CHUANXIN Z,YI S,DEGANG W. Federated learning with Gaussian differential privacy[C]//Proceedings of the 2020 2nd International Conference on Robotics,intelligent Control and Artificial Intelligence. 2020:296-301.
|
| 17 |
TAN Q, LI Q, ZHAO Y, LIU Z, et al. Defending against data reconstruction attacks in federated learning: an information theory approach[C]//33rd USENIX Security Symposium (USENIX Security 24). 2024:325-342
|
| 18 |
ZHANG J, CHEN J, WU D, et al. Poisoning attack in federated learning using generative adversarial nets[C]//2019 18th IEEE international conference on trust,security and privacy in computing and communications/13th IEEE International Conference on Big Data Science and Engineering (TrustCom/BigDataSE). IEEE,2019:374-380.
|
| 19 |
BHAGOJI A N,CHAKRABORTY S,MITTAL P,et al. Analyzing federated learning through an adversarial lens[C]//International Conference on Machine Learning. PMLR,2019:634-643.
|
| 20 |
JIANG Y,WANG S,VALLS V,et al. Model pruning enables efficient federated learning on edge devices[J]. IEEE Transactions on Neural Networks and Learning Systems,2023(34):10374-10386.
|
| 21 |
CHEN J,ZHAO Y,LI Q,et al. FedDef:defense against gradient leakage in federated learning-based network intrusion detection systems [J]. IEEE Transactions on Information Forensics and Security,2023(18):4561-4576.
|
| 22 |
ZHANG Z,XU K,LI Q,et al. Seccl:securing collaborative learning systems via trusted bulletin boards[J]. IEEE Communications Magazine,2020,58(1):47-53.
|
| 23 |
LIU Y, FAN T, CHEN T, et al. Fate: an industrial grade platform for collaborative learning with data protection[J]. The Journal of Machine Learning Research, 2021, 22 (1): 10320- 10325.
|
| 24 |
HARD A,RAO K,MATHEWS R,et al. Federated learning for mobile keyboard prediction[J]. ArXiv preprint ArXiv:1811. 03604,2018.
|
| 25 |
RYFFEL T,TRASK A,DAHL M,et al. A generic framework for privacy preserving deep learning[J]. ArXiv preprint ArXiv:1811 . 04017,2018.
|
| 26 |
HE C,LI S,SO J,et al. Fedml:a research library and benchmark for federated machine learning[J]. ArXiv preprint ArXiv:2007. 13518,2020.
|
| 27 |
MOHASSEL P, RINDAL P. ABY3:a mixed protocol framework for machine learning[C]//Proceedings of the 2018 ACM SIGSAC Conference on Computer And Communications Security. 2018: 35-52.
|
| 28 |
XIE Y,WANG Z,GAO D,et al. Federatedscope:a flexi- ble federated learning platform for heterogeneity[J]. ArXiv preprint ArXiv:2204. 05011,2022.
|
| 29 |
LIU B,TAN C,WANG J,et al. Fedlearn-algo:a flexible open- source privacy-preserving machine learning platform[J]. ArXiv preprint ArXiv:2107. 04129,2021.
|
| 30 |
MADRY A,MAKELOV A,SCHMIDT L,et al. Towards deep learning models resistant to adversarial attacks[J]. ArXiv preprint ArXiv:1706. 06083,2017.
|
| 31 |
GOODFELLOW I J,SHLENS J,SZEGEDY C. Explaining and harnessing adversarial examples[J]. ArXiv preprint ArXiv:1412. 6572,2014.
|
| 32 |
LIU Y,WEN R,HE X,et al. ML-Doctor:holistic risk assessment of inference attacks against machine learning models[C]//31st USENIX Security Symposium (USENIX Security 22). 2022:4525- 4542.
|
/
| 〈 |
|
〉 |