FedTrojan: Corrupting Federated Learning via Zero-Knowledge Federated Trojan Attacks

被引:0
作者
Chang, Shan [1 ]
Liu, Ye [1 ]
Lin, Zhijian [1 ]
Zhu, Hongzi [2 ]
Zhu, Bingzhu [1 ]
Wang, Cong [3 ]
机构
[1] Donghua Univ, Shanghai, Peoples R China
[2] Shanghai Jiao Tong Univ, Shanghai, Peoples R China
[3] City Univ Hong Kong, Hong Kong, Peoples R China
来源
2024 IEEE/ACM 32ND INTERNATIONAL SYMPOSIUM ON QUALITY OF SERVICE, IWQOS | 2024年
基金
上海市自然科学基金;
关键词
federated learning; trojan attack; quasi-trojan; zero-knowledge; semantic feature;
D O I
10.1109/IWQoS61813.2024.10682906
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Decentralized and open features of federated learning provides opportunities for malicious participants to inject stealthy trojan functionality into deep learning models collusively. A successful trojan attack is desired to be effective, precise and imperceptible, which generally requires priori knowledge such as aggregation rules, tight cooperation between attackers, e.g. sharing data distributions, and the use of inconspicuous triggers. However, in realistic, attackers are typically lack of the knowledge and hardly to fully cooperate (for privacy and efficiency reasons), and out of scope triggers are easy to be detected by scanners. We propose FedTrojan, a zero-knowledge federated trojan attack. Each attacker independently trains a quasi-trojaned local model with a self-select trigger. The model behaves normally on both regular and trojaned inputs. When local models are aggregated on the server side, the corresponding quasi-trojans will be assembled into a complete trojan which can be activated by the global trigger. We choose existing benign features rather than artificial patches as hidden local triggers to guarantee imperceptibility, and introduce catalytic features to eliminate the impact of local trojan triggers on behaviors of local/global models. Extensive experiments show that the performance of FedTrojan is significantly better than that of existing trojan attacks under both the classic FedAvg and Byzantine-robust aggregation rules.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] A Federated Weighted Learning Algorithm Against Poisoning Attacks
    Ning, Yafei
    Zhang, Zirui
    Li, Hu
    Xia, Yuhan
    Li, Ming
    International Journal of Computational Intelligence Systems, 2025, 18 (01)
  • [42] Source Inference Attacks: Beyond Membership Inference Attacks in Federated Learning
    Hu, Hongsheng
    Zhang, Xuyun
    Salcic, Zoran
    Sun, Lichao
    Choo, Kim-Kwang Raymond
    Dobbie, Gillian
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3012 - 3029
  • [43] Suppressing Poisoning Attacks on Federated Learning for Medical Imaging
    Alkhunaizi, Naif
    Kamzolov, Dmitry
    Takac, Martin
    Nandakumar, Karthik
    MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION, MICCAI 2022, PT VIII, 2022, 13438 : 673 - 683
  • [44] Distributed Backdoor Attacks in Federated Learning Generated by DynamicTriggers
    Wang, Jian
    Shen, Hong
    Liu, Xuehua
    Zhou, Hua
    Li, Yuli
    INFORMATION SECURITY THEORY AND PRACTICE, WISTP 2024, 2024, 14625 : 178 - 193
  • [45] Exploring Adversarial Attacks in Federated Learning for Medical Imaging
    Darzi, Erfan
    Dubost, Florian
    Sijtsema, Nanna. M.
    van Ooijen, P. M. A.
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (12) : 13591 - 13599
  • [46] Improved Gradient Inversion Attacks and Defenses in Federated Learning
    Geng, Jiahui
    Mou, Yongli
    Li, Qing
    Li, Feifei
    Beyan, Oya
    Decker, Stefan
    Rong, Chunming
    IEEE TRANSACTIONS ON BIG DATA, 2024, 10 (06) : 839 - 850
  • [47] Membership Inference Attacks and Defenses in Federated Learning: A Survey
    Bai, Li
    Hu, Haibo
    Ye, Qingqing
    Li, Haoyang
    Wang, Leixia
    Xu, Jianliang
    ACM COMPUTING SURVEYS, 2025, 57 (04)
  • [48] Attacks against Federated Learning Defense Systems and their Mitigation
    Lewis, Cody
    Varadharajan, Vijay
    Noman, Nasimul
    JOURNAL OF MACHINE LEARNING RESEARCH, 2023, 24
  • [49] Towards Practical Backdoor Attacks on Federated Learning Systems
    Shi, Chenghui
    Ji, Shouling
    Pan, Xudong
    Zhang, Xuhong
    Zhang, Mi
    Yang, Min
    Zhou, Jun
    Yin, Jianwei
    Wang, Ting
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (06) : 5431 - 5447
  • [50] OASIS: Offsetting Active Reconstruction Attacks in Federated Learning
    Jeter, Tre' R.
    Nguyen, Truc
    Alharbi, Raed
    Thai, My T.
    2024 IEEE 44TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, ICDCS 2024, 2024, : 1004 - 1015