Journal on Communications ›› 2023, Vol. 44 ›› Issue (8): 1-13.doi: 10.11959/j.issn.1000-436x.2023149

• Papers •    

Adversarial sample generation algorithm for vertical federated learning

Xiaolin CHEN1,2, Daoguang ZAN1,2, Bingchao WU1,2, Bei GUAN2,3, Yongji WANG2,3   

  1. 1 Collaborative Innovation Center, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
    2 University of Chinese Academy of Sciences, School of Computer Science and Technology, Beijing 100049, China
    3 Integrated Innovation Center, Institute of Software, Chinese Academy of Sciences, Beijing 100190, China
  • Revised:2023-07-25 Online:2023-08-01 Published:2023-08-01
  • Supported by:
    The National Natural Science Foundation of China(61762062)

Abstract:

To adapt to the scenario characteristics of vertical federated learning (VFL) applications regarding high communication cost, fast model iteration, and decentralized data storage, a generalized adversarial sample generation algorithm named VFL-GASG was proposed.Specifically, an adversarial sample generation framework was constructed for the VFL architecture.A white-box adversarial attack in the VFL was implemented by extending the centralized machine learning adversarial sample generation algorithm with different policies such as L-BFGS, FGSM, and C&W.By introducing deep convolutional generative adversarial network (DCGAN), an adversarial sample generation algorithm named VFL-GASG was designed to address the problem of universality in the generation of adversarial perturbations.Hidden layer vectors were utilized as local prior knowledge to train the adversarial perturbation generation model, and through a series of convolution-deconvolution network layers, finely crafted adversarial perturbations were produced.Experiments show that VFL-GASG can maintain a high attack success while achieving a higher generation efficiency, robustness, and generalization ability than the baseline algorithm, and further verify the impact of relevant settings for adversarial attacks.

Key words: machine learning, VFL, adversarial sample, adversarial attack, DCGAN

CLC Number: 

No Suggested Reading articles found!