Label-Flipping Attacks in GNN-Based Federated Learning

被引:0
|
作者
Yu, Shanqing [1 ,2 ]
Shen, Jie [1 ,2 ]
Xu, Shaocong [1 ,2 ]
Wang, Jinhuan [1 ,2 ]
Wang, Zeyu [1 ,2 ]
Xuan, Qi [1 ,2 ]
机构
[1] Zhejiang Univ Technol, Inst Cyberspace Secur, Coll Informat Engn, Hangzhou 310014, Peoples R China
[2] Zhejiang Univ Technol, Binjiang Inst Artificial Intelligence, Hangzhou 310056, Peoples R China
来源
IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING | 2025年 / 12卷 / 02期
基金
中国国家自然科学基金;
关键词
Federated learning; Security; Computational modeling; Training; Data models; Graph neural networks; Data privacy; Costs; Symbols; Robustness; graph neural network; label-flipping; data poisoning;
D O I
10.1109/TNSE.2025.3528831
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
Federated learning offers multi-party collaborative training but also poses several potential security risks. These security issues have been studied more extensively in the context of basic image models, but it is relatively less explored in the field of graphs. Compared to various existing graph-based attack methods, the label-flipping attack does not need to change the graph structure and it is highly stealthy. Therefore, this paper explores a Graph Federated Label Flipping Attack (Graph-FLFA) and proposes a new malicious gradient computation strategy for federated graph models. The goal of this attack method is to maximally disrupt the classification results of specific nodes in the node classification task, without affecting the classification performance of other nodes. This strategy exhibits strong specificity and stealthiness, effectively balancing the influence of various labels and ensuring significant attack effects even when the poisoning ratio is very low. Extensive experiments on four benchmark datasets demonstrate that Graph-FLFA has a high attack success rate in different GNN-based models, achieving the most advanced attack performance. Furthermore, it has the capability to evade detection methods employed in defensive measures.
引用
收藏
页码:1357 / 1368
页数:12
相关论文
共 50 条
  • [1] Systematic Analysis of Label-flipping Attacks against Federated Learning in Collaborative Intrusion Detection Systems
    Lavaur, Leo
    Busnel, Yann
    Autrel, Fabien
    19TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY, AND SECURITY, ARES 2024, 2024,
  • [2] LFighter: Defending against the label-flipping attack in federated learning
    Jebreel, Najeeb Moharram
    Domingo-Ferrer, Josep
    Sanchez, David
    Blanco-Justicia, Alberto
    NEURAL NETWORKS, 2024, 170 : 111 - 126
  • [3] Privacy-Preserving Federated Learning Against Label-Flipping Attacks on Non-IID Data
    Shen, Xicong
    Liu, Ying
    Li, Fu
    Li, Chunguang
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (01): : 1241 - 1255
  • [4] Edge-Assisted Label-Flipping Attack Detection in Federated Learning
    Alotaibi, Nourah S.
    Felemban, Muhamad
    Mahmood, Sajjad
    IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY, 2024, 5 : 7278 - 7300
  • [5] Robust Federated Learning for execution time-based device model identification under label-flipping attack
    Sanchez Sanchez, Pedro Miguel
    Huertas Celdran, Alberto
    Buendia Rubio, Jose Rafael
    Bovet, Gerome
    Martinez Perez, Gregorio
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (01): : 313 - 324
  • [6] Robust Federated Learning for execution time-based device model identification under label-flipping attack
    Pedro Miguel Sánchez Sánchez
    Alberto Huertas Celdrán
    José Rafael Buendía Rubio
    Gérôme Bovet
    Gregorio Martínez Pérez
    Cluster Computing, 2024, 27 : 313 - 324
  • [7] GNN-based Neighbor Selection and Resource Allocation for Decentralized Federated Learning
    Meng, Chuiyang
    Tang, Ming
    Setayesh, Mehdi
    Wong, Vincent W. S.
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 1223 - 1228
  • [8] A Robust Detection and Correction Framework for GNN-Based Vertical Federated Learning
    Yang, Zhicheng
    Fan, Xiaoliang
    Wang, Zheng
    Wang, Zihui
    Wang, Cheng
    PATTERN RECOGNITION AND COMPUTER VISION, PRCV 2023, PT III, 2024, 14427 : 97 - 108
  • [9] Detection and Mitigation of Label-Flipping Attacks in FL Systems With KL Divergence
    Zang, Liguang
    Li, Yuancheng
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (19): : 32221 - 32233
  • [10] Label flipping attacks in hierarchical federated learning for intrusion detection in IoT
    Elmahfoud, Ennaji
    El Hajla, Salah
    Maleh, Yassine
    Mounir, Soufyane
    Ouazzane, Karim
    INFORMATION SECURITY JOURNAL, 2024,