面向无人机网络的联邦层次聚类防御方法
网络出版日期: 2025-03-19
基金资助
国家自然科学基金联合基金项目国际(地区)合作与交流项目(62261160651);国家自然科学基金联合基金(U21A20464,U23A20307);国家自然科学基金青年基金(62406239)
版权
A federated hierarchical clustering defense method for UAV networks
Online published: 2025-03-19
Copyright
随着物联网技术的发展,无人机(Unmanned Aerial Vehicle,UAV)辅助边缘计算对于提高数据处理能力和模型性能至关重要。但无人机节点计算和存储能力不足限制了本地模型的质量,无法有效支撑神经网络模型的训练任务,引入联邦学习机制构建无人机群可以有效解决这一问题。但是这一过程涉及系统可用性和隐私保护的权衡,导致投毒攻击更易生效且更加隐蔽。传统的聚合防御方案通过引入相似性或梯度贡献评估来筛选恶意梯度,从而抵御投毒攻击的威胁,但近年来自适应投毒攻击的出现使得此类防御方法不再有效。因此,为了更好地防御模型投毒攻击,提出了一种基于层次聚类的聚合算法,通过自底向上对梯度进行处理,实现无人机群对各类投毒攻击的通用性防护。在三个常用的数据集上评估了不同攻击场景下的防御效果,与现有方案相比,本文方案的平均防御成功率提高了11.25%,模型准确率平均提高了2.8%。
刘洋 , 卢源斌 , 杨易龙 , 刘心晶 , 马卓 , 马建峰 . 面向无人机网络的联邦层次聚类防御方法[J]. 网络空间安全科学学报, 2025 , 3(1) : 30 -41 . DOI: 10.20172/j.issn.2097-3136.250103
With the rapid development of Internet of Things (IoT) technology, the unmanned aerial vehicle (UAV)-assisted edge computing has become crucial for enhancing data processing capabilities and model performance. However, the limited computational and storage capacities of UAV nodes constrain the quality of local models, making them insufficient to support the neural network training tasks effectively. To address this challenge, introducing a federated learning mechanism to construct UAV swarms has proven to be an effective solution. Nevertheless, this approach involves trade-offs between the system availability and the privacy protection, which make poisoning attacks more effective and harder to detect. Traditional aggregation defense mechanisms mitigate the threat of poisoning attacks by introducing similarity or gradient contribution evaluation to filter out malicious gradients. However, the emergence of adaptive poisoning attacks in recent years has rendered such defenses less effective. To better counter the model poisoning attacks, a hierarchical clustering-based aggregation algorithm was proposed. By processing gradients in a bottom-up manner, the algorithm enhanced the UAV swarm’s robustness against various types of poisoning attacks. Experimental evaluations on three commonly used datasets demonstrated the effectiveness of the proposed method across different attack scenarios. Compared with existing approaches, the proposed method improved the average defense success rate by 11.25% and increased the model accuracy by an average of 2.8%.
表 1 不同攻击场景下聚合算法的全局模型准确率Table 1 Global model accuracy of aggregation algorithms under different attack scenarios |
| 数据集(分布) | 模型投毒攻击 | 鲁棒聚合算法 | ||
| Krum | Trmean | 本方案 | ||
| MNIST(IID) | 无攻击 | |||
| Fang攻击 | ||||
| Shejwalkar攻击 | ||||
| Fashion-MNIST(IID) | 无攻击 | |||
| Fang攻击 | ||||
| Shejwalkar攻击 | ||||
| CIFAR-10(IID) | 无攻击 | |||
| Fang攻击 | ||||
| Shejwalkar攻击 | | NaN | ||
| MNIST(Non-IID) | 无攻击 | |||
| Fang攻击 | ||||
| Shejwalkar攻击 | ||||
| Fashion-MNIST(Non-IID) | 无攻击 | |||
| Fang攻击 | ||||
| Shejwalkar攻击 | ||||
| CIFAR-10(Non-IID) | 无攻击 | |||
| Fang攻击 | NaN | |||
| Shejwalkar攻击 | NaN | NaN | ||
图 3 聚合算法在MNIST数据集上的全局模型准确率Fig.3 Global model accuracy of the aggregation algorithm on the MNIST dataset |
图 4 聚合算法在Fashion-MNIST数据集上的全局模型准确率Fig.4 Global model accuracy of the aggregation algorithm on the Fashion-MNIST dataset |
①
| 1 |
VILLAMIL S, HERNáNDEZ C, TARAZONA G. An overview of internet of things[J]. Telkomnika (Telecommunication Computing Electronics and Control), 2020, 18 (5): 2320- 2327.
|
| 2 |
ARISDAKESSIAN S, WAHAB O A, MOURAD A, et al. A survey on IoT intrusion detection: Federated learning, game theory, social psychology, and explainable AI as future directions[J]. IEEE Internet of Things Journal, 2022, 10 (5): 4059- 4092.
|
| 3 |
SAMI H, OTROK H, BENTAHAR J, et al. AI-based resource provisioning of IoE services in 6G: A deep reinforcement learning approach[J]. IEEE Transactions on Network and Service Management, 2021, 18 (3): 3527- 3540.
|
| 4 |
EMIMI M,KHALEEL M,ALKRASH A. The current opportunities and challenges in drone technology[J]. International Journal of Electrical Engineering and Sustainability,2023,1(2):74-89.
|
| 5 |
HAFEEZ A, HUSAIN M A, SINGH S P, et al. Implementation of drone technology for farm monitoring & pesticide spraying: A review[J]. Information Processing in Agriculture, 2023, 10 (2): 192- 203.
|
| 6 |
SHAH I A,LARAIB A,ASHRAF H,et al. Drone technology:Current challenges and opportunities[J]. Cybersecurity Issues and Challenges in the Drone Industry,2024:343-361.
|
| 7 |
MCMAHAN B,MOORE E,RAMAGE D,et al. Communication-efficient learning of deep networks from decentralized data[C]//Artificial Intelligence and Statistics. PMLR,2017:1273-1282.
|
| 8 |
WAZZEH M, OULD-SLIMANE H, TALHI C, et al. Privacy-preserving continuous authentication for mobile and IoT systems using warmup-based federated learning[J]. IEEE Network, 2022, 37 (3): 224- 230.
|
| 9 |
曹嵘晖, 唐卓, 左知微, 等. 面向机器学习的分布式并行计算关键技术及应用[J]. 智能系统学报, 2021, 16 (5): 919- 930.
CAO R H, TANG Z, ZUO Z W, et al. Key technologies and applications of distributed parallel computing for machine learning[J]. CAAI Transactions on Intelligent Systems, 2021, 16 (5): 919- 930.
|
| 10 |
ZHENG M,XU D,JIANG L,et al. Challenges of privacy-preserving machine learning in IoT[C]//Proceedings of the First International Workshop on Challenges in Artificial Intelligence and Machine Learning for Internet of Things. 2019:1-7.
|
| 11 |
ZENG T,SEMIARI O,MOZAFFARI M,et al. Federated learning in the sky:Joint power allocation and scheduling with UAV swarms[C]//ICC 2020-2020 IEEE International Conference on Communications (ICC). IEEE,2020:1-6.
|
| 12 |
ALSAMHI S H, ALMALKI F A, AFGHAH F, et al. Drones’ edge intelligence over smart environments in B5G: Blockchain and federated learning synergy[J]. IEEE Transactions on Green Communications and Networking, 2021, 6 (1): 295- 312.
|
| 13 |
BRIK B, KSENTINI A, BOUAZIZ M. Federated learning for UAVs-enabled wireless networks: Use cases, challenges, and open problems[J]. IEEE Access, 2020, 8, 53841- 53849.
|
| 14 |
FU M, SHI Y, ZHOU Y. Federated learning via unmanned aerial vehicle[J]. IEEE Transactions on Wireless Communications,2023,23(4):2884-2900.
|
| 15 |
DRAINAKIS G,KATSAROS K V,PANTAZOPOULOS P,et al. Federated vs. centralized machine learning under privacy-elastic users:A comparative analysis[C]//2020 IEEE 19th International Symposium on Network Computing and Applications (NCA). IEEE,2020:1-8.
|
| 16 |
孙爽,李晓会,刘妍,等. 不同场景的联邦学习安全与隐私保护研究综述[J]. 计算机应用研究,2021,38(12):3527.
SUN S,LI X H,LIU Y,et al. Survey on security and privacy protection in different scenarios of federated learning [J]. Application Research of Computers,2021,38(12):3527.
|
| 17 |
CAO X,GONG N Z. Mpaf:Model poisoning attacks to federated learning based on fake clients[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. 2022:3396-3404.
|
| 18 |
MA X, ZHU J, LIN Z, et al. A state-of-the-art survey on solving non-IID data in federated learning[J]. Future Generation Computer Systems, 2022, 135, 244- 258.
|
| 19 |
BLANCHARD P,EL MHAMDI E M,GUERRAOUI R,et al. Machine learning with adversaries:Byzantine tolerant gradient descent[J]. Advances in Neural Information Processing Systems,2017,30.
|
| 20 |
YIN D,CHEN Y,KANNAN R,et al. Byzantine-robust distributed learning:Towards optimal statistical rates[C]//International Conference on Machine Learning. PMLR,2018:5650-5659.
|
| 21 |
FUNG C,YOON C J M,BESCHASTNIKH I. The limitations of federated learning in sybil settings[C]//23rd International Symposium on Research in Attacks,Intrusions and Defenses (RAID 2020). 2020:301-316.
|
| 22 |
徐浩曈,刘立新,王静宇,等. 一种基于区块链的联邦学习贡献评价方案[J]. 计算机应用研究,2023,40(8):2258.
XU H T,LIU L X,WANG J Y,et al. Blockchain-based contribution evaluation scheme for federated learning [J]. Application Research of Computers,2023,40(8):2258.
|
| 23 |
CAO X, FANG M, LIU J, et al. Fltrust: Byzantine-robust federated learning via trust bootstrapping[J]. arXiv preprint, arXiv:, 2012, 13995, 2020.
|
| 24 |
XIE C,KOYEJO S,GUPTA I. Zeno++:Robust fully asynchronous SGD[C]//International Conference on Machine Learning. PMLR,2020:10495-10503.
|
| 25 |
ZHANG S,LI J,SHI L,et al. Federated learning in intelligent transportation systems:Recent applications and open problems[J]. IEEE Transactions on Intelligent Transportation Systems, 2023,25(5):3259-3285.
|
| 26 |
CHHIKARA P, TEKCHANDANI R, KUMAR N, et al. Federated learning and autonomous UAVs for hazardous zone detection and AQI prediction in IoT environment[J]. IEEE Internet of Things Journal, 2021, 8 (20): 15456- 15467.
|
| 27 |
SEID A M, ERBAD A, ABISHU H N, et al. Multiagent federated reinforcement learning for resource allocation in UAV-enabled internet of medical things networks[J]. IEEE Internet of Things Journal, 2023, 10 (22): 19695- 19711.
|
| 28 |
刘建华,王可心,涂晓光,等. 融合差分隐私联邦学习的无人机辅助边缘计算任务调度[J/OL].电讯技术,1-11[2024-12-06]. https://doi.org/10.20079/j.issn.1001-893x.240530002.
LIU J H,WANG K X,TU X G,et al. UAV-Assisted Edge Computing Task Scheduling with Differential Privacy Federated Learning[J/OL]. Telecommunication Engineering,1-11[2024-12-06]. https://doi.org/10.20079/j.issn.1001-893x.240530002.
|
| 29 |
TURSUNBOEV J, KANG Y S, HUH S B, et al. Hierarchical federated learning for edge-aided unmanned aerial vehicle networks[J]. Applied Sciences, 2022, 12 (2): 670.
|
| 30 |
卢彦丰, 吴韬, 刘春生, 等. 无人机辅助的高能效边缘联邦学习综述[J]. 计算机科学, 2024, 51 (4): 270- 279.
LU Y S, WU T, LIU C S, et al. Survey of UAV-assisted energy-efficient edge federated learning[J]. Computer Science, 2024, 51 (4): 270- 279.
|
| 31 |
LIM W Y B, LUONG N C, HOANG D T, et al. Federated learning in mobile edge networks: A comprehensive survey[J]. IEEE Communications Surveys & Tutorials, 2020, 22 (3): 2031- 2063.
|
| 32 |
NI S,HE Y,CHEN L,et al. A survey of edge computing resource allocation strategies based on federated learning[C]//2023 International Conference on Networking and Network Applications (NaNA). IEEE,2023:116-121.
|
| 33 |
ZHANG C, XIE Y, BAI H, et al. A survey on federated learning[J]. Knowledge-Based Systems, 2021, 216, 106775.
|
| 34 |
FANG M,CAO X,JIA J,et al. Local model poisoning attacks to {Byzantine-Robust} federated learning[C]//29th USENIX Security Symposium (USENIX Security 20). 2020:1605-1622.
|
| 35 |
SHEJWALKAR V,HOUMANSADR A. Manipulating the byzantine:Optimizing model poisoning attacks and defenses for federated learning[C]//Network and Distributed Systems Security (NDSS) Symposium. 2021:21-24.
|
| 36 |
BOTTOU L,CORTES C,DENKER J S,et al. Comparison of classifier methods:A case study in handwritten digit recognition[C]//Proceedings of the 12th IAPR International Conference on Pattern Recognition. IEEE,1994,2:77-82.
|
| 37 |
XIAO H, RASUL K, VOLLGRAF R. Fashion-MNIST: a novel image dataset for benchmarking machine learning algorithms[J]. arXiv preprint, arXiv:, 1708, 07747, 2017.
|
| 38 |
KRIZHEVSKY A, SUTSKEVER I, HINTON G E. Imagenet classification with deep convolutional neural networks[J]. Advances in Neural Information Processing Systems, 2012, 25, 1097- 1105.
|
| 39 |
HSU T M H, QI H, BROWN M. Measuring the effects of non-identical data distribution for federated visual classification[J]. ArXiv preprint, ArXiv:, 1909, 06335, 2019.
|
/
| 〈 |
|
〉 |