ANODYNE: Mitigating backdoor attacks in federated learning

被引:1
|
作者
Gu, Zhipin [1 ]
Shi, Jiangyong [1 ]
Yang, Yuexiang [1 ]
机构
[1] Natl Univ Def Technol, 109 Deya Rd, Changsha 410000, Hunan, Peoples R China
关键词
Federated learning; Backdoor attacks; Security and robustness;
D O I
10.1016/j.eswa.2024.125359
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning (FL) allows participants to jointly train a model without leaking their sensitive datasets. The server is designed to have no visibility into how these updates are generated for privacy protection. Despite its benefits, FL is vulnerable to backdoor attacks, in which the compromised participants upload malicious model updates so that the backdoored model will misbehave for the chosen subtask. Existing defenses against backdoor attacks cannot handle state-of-the-art backdoor attacks that insert the backdoor in all rounds. To address these issues, we propose ANODYNE, a defense framework that hierarchically filters and clips the local model updates to mitigate the effect of backdoor attacks. ANODYNE decomposes the high- dimensional gradients into low-dimensional sub-vectors to improve detection performance and avoid the curse of dimensionality. Meanwhile, ANODYNE computes four different sub-vector metrics from a spatial-temporal perspective to enhance the robustness of our method. Our evaluation of ANODYNE on three datasets and three models demonstrates that ANODYNE competes over existing defenses under backdoor attacks.
引用
收藏
页数:9
相关论文
共 50 条
  • [41] Resisting Backdoor Attacks in Federated Learning via Bidirectional Elections and Individual Perspective
    Qin, Zhen
    Chen, Feiyi
    Zhi, Chen
    Yan, Xueqiang
    Deng, Shuiguang
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 13, 2024, : 14677 - 14685
  • [42] Coordinated Backdoor Attacks against Federated Learning with Model-Dependent Triggers
    Gong, Xueluan
    Chen, Yanjiao
    Huang, Huayang
    Liao, Yuqing
    Wang, Shuai
    Wang, Qian
    IEEE NETWORK, 2022, 36 (01): : 84 - 90
  • [43] FedGame: A Game-Theoretic Defense against Backdoor Attacks in Federated Learning
    Jia, Jinyuan
    Yuan, Zhuowen
    Sahabandu, Dinuka
    Niu, Luyao
    Rajabi, Arezoo
    Ramasubramanian, Bhaskar
    Li, Bo
    Poovendran, Radha
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [44] Shielding Federated Learning: Mitigating Byzantine Attacks with Less Constraints
    Li, Minghui
    Wan, Wei
    Lu, Jianrong
    Hu, Shengshan
    Shi, Junyu
    Zhang, Leo Yu
    Zhou, Man
    Zheng, Yifeng
    2022 18TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING, MSN, 2022, : 178 - 185
  • [45] Mitigating Gradient Inversion Attacks in Federated Learning with Frequency Transformation
    Palihawadana, Chamath
    Wiratunga, Nirmalie
    Kalutarage, Harsha
    Wijekoon, Anjana
    COMPUTER SECURITY. ESORICS 2023 INTERNATIONAL WORKSHOPS, CPS4CIP, PT II, 2024, 14399 : 750 - 760
  • [46] FLEDGE: Ledger-based Federated Learning Resilient to Inference and Backdoor Attacks
    Castillo, Jorge
    Rieger, Phillip
    Fereidooni, Hossein
    Chen, Qian
    Sadeghi, Ahmad-Reza
    39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 647 - 661
  • [47] Backdoor attacks and defenses in federated learning: Survey, challenges and future research directions
    Nguyen, Thuy Dung
    Nguyen, Tuan
    Nguyen, Phi Le
    Pham, Hieu H.
    Doan, Khoa D.
    Wong, Kok-Seng
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 127
  • [48] Mitigating Adversarial Attacks in Federated Learning with Trusted Execution Environments
    Queyrut, Simon
    Schiavoni, Valerio
    Felber, Pascal
    2023 IEEE 43RD INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, ICDCS, 2023, : 626 - 637
  • [49] Edge-Cloud Collaborative Defense against Backdoor Attacks in Federated Learning
    Yang, Jie
    Zheng, Jun
    Wang, Haochen
    Li, Jiaxing
    Sun, Haipeng
    Han, Weifeng
    Jiang, Nan
    Tan, Yu-An
    SENSORS, 2023, 23 (03)
  • [50] Resisting Distributed Backdoor Attacks in Federated Learning: A Dynamic Norm Clipping Approach
    Guo, Yifan
    Wang, Qianlong
    Ji, Tianxi
    Wang, Xufei
    Li, Pan
    2021 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2021, : 1172 - 1182