# FedEM Attack Analysis

TJ Kim
11.5.21

#### Summary:
- Load the locally trained model and FedEM model
- nodes = 3, mixtures = 3

In [1]:
cd /home/ubuntu/FedEM/

/home/ubuntu/FedEM


### Import Relevant Libraries
Take it from the run_experiment.py folder

In [2]:
# Import General Libraries
import os
import argparse
import torch
import copy
import pickle
import random
import numpy as np
import pandas as pd

# Import FedEM based Libraries
from utils.utils import *
from utils.constants import *
from utils.args import *
from torch.utils.tensorboard import SummaryWriter
from run_experiment import *
from models import *

# Import Transfer Attack
from transfer_attacks.Personalized_NN import *
from transfer_attacks.Params import *
from transfer_attacks.Transferer import *
from transfer_attacks.Args import *

### Generate Aggregator Pre-requisite
- Clients, Test Clients, Ensemble_Learner
- Follow through the code in run_experiment.py

In [3]:
# Manually set argument parameters
args_ = Args()
args_.experiment = "cifar10"
args_.method = "FedEM"
args_.decentralized = False
args_.sampling_rate = 1.0
args_.input_dimension = None
args_.output_dimension = None
args_.n_learners= 3
args_.n_rounds = 10
args_.bz = 128
args_.local_steps = 1
args_.lr_lambda = 0
args_.lr =0.03
args_.lr_scheduler = 'multi_step'
args_.log_freq = 10
args_.device = 'cuda'
args_.optimizer = 'sgd'
args_.mu = 0
args_.communication_probability = 0.1
args_.q = 1
args_.locally_tune_clients = False
args_.seed = 1234
args_.verbose = 1
args_.save_path = 'weights/cifar/21_09_28_first_transfers/'
args_.validation = False

# Generate the dummy values here
aggregator, clients = dummy_aggregator(args_)

==> Clients initialization..
===> Building data iterators..


100%|██████████████████████████████████████████| 80/80 [00:00<00:00, 148.48it/s]


===> Initializing clients..


100%|███████████████████████████████████████████| 80/80 [01:01<00:00,  1.31it/s]


==> Test Clients initialization..
===> Building data iterators..


0it [00:00, ?it/s]


===> Initializing clients..


0it [00:00, ?it/s]


++++++++++++++++++++++++++++++
Global..
Train Loss: 2.292 | Train Acc: 12.050% |Test Loss: 2.292 | Test Acc: 12.681% |
++++++++++++++++++++++++++++++++++++++++++++++++++
################################################################################


In [4]:
# Import weights for aggregator
aggregator.load_state(args_.save_path)

# This is where the models are stored -- one for each mixture --> learner.model for nn
hypotheses = aggregator.global_learners_ensemble.learners

# obtain the state dict for each of the weights 
weights_h = []

for h in hypotheses:
    weights_h += [h.model.state_dict()]

In [11]:
weights = np.load("weights/cifar/21_09_28_first_transfers/train_client_weights.npy")
np.set_printoptions(formatter={'float': lambda x: "{0:0.2f}".format(x)})

#print(weights)

# Set model weights
model_weights = []
num_models = 5

for i in range(num_models):
    model_weights += [weights[i]]
    
    
# Generate the weights to test on as linear combinations of the model_weights
models_test = []

for (w0,w1,w2) in model_weights:
    # first make the model with empty weights
    new_model = copy.deepcopy(hypotheses[0].model)
    new_model.eval()
    new_weight_dict = copy.deepcopy(weights_h[0])
    for key in weights_h[0]:
        new_weight_dict[key] = w0*weights_h[0][key] + w1*weights_h[1][key] + w2*weights_h[2][key]
    new_model.load_state_dict(new_weight_dict)
    models_test += [new_model]

### Generate Data 

In [12]:
# Combine Validation Data across all clients as test
data_x = []
data_y = []

for i in range(len(clients)):
    daniloader = clients[i].val_iterator
    for (x,y,idx) in daniloader.dataset:
        data_x.append(x)
        data_y.append(y)

data_x = torch.stack(data_x)
data_y = torch.stack(data_y)

In [13]:
# Create dataloader from validation dataset that allows for diverse batch size
dataloader = Custom_Dataloader(data_x, data_y)

### Set Up Transfer Attack Scenario
- Set up order of which attacks will take place -- keep the same transferer, but simply swap out the weights of the adversary and flush out the existing data points analysis was done on
- Make dictionaries beforehand recording all of the metrics

In [14]:
# Set Up Dictionaries -- list holds the adversary idx
logs_adv = []

for i in range(len(model_weights)):
    adv_dict = {}
    adv_dict['orig_acc_transfers'] = None
    adv_dict['orig_similarities'] = None
    adv_dict['adv_acc_transfers'] = None
    adv_dict['adv_similarities'] = None
    adv_dict['orig_target_hit'] = None
    adv_dict['adv_target_hit'] = None
    adv_dict['metric_variance'] = None
    adv_dict['metric_alignment'] = None
    adv_dict['metric_ingrad'] = None
    logs_adv += [adv_dict]

In [15]:
# Make transferer and Assign model index
victim_idxs = [0,1,2,3,4]

for adv_idx in victim_idxs:
    print("id", adv_idx)
    # Perform Attack
    t1 = Transferer(models_list=models_test, dataloader=dataloader)
    t1.generate_victims(victim_idxs)
    t1.generate_advNN(adv_idx)
    t1.generate_xadv(atk_type = "ifsgm")
    t1.send_to_victims(victim_idxs)
    t1.check_empirical_metrics(orig_flag = True)
    t1.check_empirical_metrics()
    
    # Log Performance
    logs_adv[adv_idx]['orig_acc_transfers'] = t1.orig_acc_transfers
    logs_adv[adv_idx]['orig_similarities'] = t1.orig_similarities
    logs_adv[adv_idx]['adv_acc_transfers'] = t1.adv_acc_transfers
    logs_adv[adv_idx]['adv_similarities'] = t1.adv_similarities
    logs_adv[adv_idx]['orig_target_hit'] = t1.orig_target_hit
    logs_adv[adv_idx]['adv_target_hit'] = t1.adv_target_hit
    
    logs_adv[adv_idx]['metric_variance'] = t1.metric_variance
    logs_adv[adv_idx]['metric_alignment'] = t1.metric_alignment
    logs_adv[adv_idx]['metric_ingrad'] = t1.metric_ingrad

id 0
id 1
id 2
id 3
id 4


### Print and Record Results
- Organize the results into a matrix and print them into an excel sheet
- Following Categories (sim_benign, sim_adv, target_adv,grad_alignment)

In [16]:
metrics = ['orig_similarities','adv_similarities','adv_target_hit','metric_alignment']

sim_benign = np.zeros([len(victim_idxs),len(victim_idxs)]) 
sim_adv = np.zeros([len(victim_idxs),len(victim_idxs)]) 
target_adv = np.zeros([len(victim_idxs),len(victim_idxs)]) 
grad_align = np.zeros([len(victim_idxs),len(victim_idxs)]) 

In [17]:
for adv_idx in victim_idxs:
    for victim in victim_idxs:
        sim_benign[adv_idx,victim] = logs_adv[adv_idx][metrics[0]][victim].data.tolist()
        sim_adv[adv_idx,victim] = logs_adv[adv_idx][metrics[1]][victim].data.tolist()
        target_adv[adv_idx,victim] = logs_adv[adv_idx][metrics[2]][victim].data.tolist()
        grad_align[adv_idx,victim] = logs_adv[adv_idx][metrics[3]][victim].data.tolist()

In [18]:
# Save to Excel file

## convert your array into a dataframe
sim_benign_df = pd.DataFrame(sim_benign)
sim_adv_df = pd.DataFrame(sim_adv)
target_adv_df = pd.DataFrame(target_adv)
grad_align_df = pd.DataFrame(grad_align)

## save to xlsx file

#filepath = 'my_excel_file.xlsx'

# df.to_excel(filepath, index=False)

In [19]:
sim_benign_df

Unnamed: 0,0,1,2,3,4
0,1.0,0.774,0.856,0.648,0.754
1,0.77,1.0,0.778,0.718,0.752
2,0.816,0.81,1.0,0.81,0.904
3,0.658,0.718,0.772,1.0,0.89
4,0.754,0.762,0.886,0.864,1.0


In [20]:
sim_adv_df

Unnamed: 0,0,1,2,3,4
0,1.0,0.602,0.88,0.354,0.674
1,0.834,1.0,0.836,0.59,0.72
2,0.906,0.714,1.0,0.56,0.894
3,0.618,0.616,0.76,1.0,0.814
4,0.838,0.686,0.95,0.762,1.0


In [21]:
target_adv_df

Unnamed: 0,0,1,2,3,4
0,0.896,0.502,0.78,0.26,0.576
1,0.608,0.708,0.584,0.358,0.486
2,0.752,0.534,0.796,0.394,0.708
3,0.406,0.382,0.518,0.702,0.554
4,0.696,0.524,0.798,0.584,0.794


In [22]:
grad_align_df

Unnamed: 0,0,1,2,3,4
0,0.0,1.166321,0.961014,1.302881,1.108785
1,1.183839,0.0,1.120392,1.162302,1.131657
2,0.998951,1.134299,0.0,1.172681,0.726881
3,1.34474,1.189158,1.169994,0.0,1.032213
4,1.158448,1.149938,0.726378,1.025656,0.0


In [25]:
# Average all the information together and present
sim_benign_mean = np.mean((sim_benign.sum(1)-1)/(sim_benign.shape[1]-1))
sim_adv_mean = np.mean((sim_adv_df.sum(1)-1)/(sim_adv_df.shape[1]-1))
target_adv_mean = np.mean((target_adv.sum(1)-1)/(target_adv.shape[1]-1))
grad_align_mean = np.mean((grad_align.sum(1)-1)/(grad_align.shape[1]-1))

print("Sim Benign Mean", sim_benign_mean)
print("Sim ADV Mean", sim_adv_mean)
print("Target ADV Mean", target_adv_mean)
print("Grad Align Mean", grad_align_mean)

Sim Benign Mean 0.7847000390291214
Sim ADV Mean 0.7304000362753869
Target ADV Mean 0.4950000375509262
Grad Align Mean 0.8483263492584229
