Dual-domain based backdoor attack against federated learning

被引:1
|
作者
Li, Guorui [1 ,2 ]
Chang, Runxing [1 ]
Wang, Ying [3 ]
Wang, Cong [1 ,2 ]
机构
[1] Northeastern Univ, Sch Comp Sci & Engn, Shenyang 110819, Peoples R China
[2] Northeastern Univ Qinhuangdao, Hebei Key Lab Marine Percept Network & Data Proc, Qinhuangdao 066004, Peoples R China
[3] Qinhuangdao Vocat & Tech Coll, Dept Informat Engn, Qinhuangdao 066100, Peoples R China
关键词
Backdoor attack; Federated learning; Frequency domain; Spatial domain; Trigger;
D O I
10.1016/j.neucom.2025.129424
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The distributed training feature and data heterogeneity in federated learning (FL) render it susceptible to various threats, in which the backdoor attack stands out as the most destructive one. By injecting malicious functionality into the global model through poisoned updates, backdoor attacks can generate attacker-desired inference results on the trigger-embedded inputs while behaving normally on other data instances. The current backdoor triggers are of significant visual features that can be easily identified by humans or computers. Meanwhile, the common model update clipping mechanism is too simple and straightforward to be recognized by various defense methods with ease. Aiming at the above shortcomings, we proposed a dual-domain based backdoor attack (DDBA) against FL in this paper. On the one hand, DDBA generates an imperceptible dual- domain trigger for any image by superimposing in its low-frequency region of the amplitude spectrum and then applying a slight spatial distortion subsequently. On the other hand, DDBA truncates the model update dynamically based on a newly designed adaptive clipping mechanism to enhance its stealthiness. Finally, we carried out extensive experiments to evaluate the attack performance and stealth performance of DDBA on four publicly available datasets. The experiment results show that DDBA has excellent attack performance in both single-shot and multiple-shot attack scenarios as well as robust stealth performance under the existing defense methods against backdoor attacks.
引用
收藏
页数:12
相关论文
共 50 条
  • [21] DEFENDING AGAINST BACKDOOR ATTACKS IN FEDERATED LEARNING WITH DIFFERENTIAL PRIVACY
    Miao, Lu
    Yang, Wei
    Hu, Rong
    Li, Lu
    Huang, Liusheng
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 2999 - 3003
  • [22] A Blockchain-Based Federated-Learning Framework for Defense against Backdoor Attacks
    Li, Lu
    Qin, Jiwei
    Luo, Jintao
    ELECTRONICS, 2023, 12 (11)
  • [23] BADFL: Backdoor Attack Defense in Federated Learning From Local Model Perspective
    Zhang, Haiyan
    Li, Xinghua
    Xu, Mengfan
    Liu, Ximeng
    Wu, Tong
    Weng, Jian
    Deng, Robert H.
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (11) : 5661 - 5674
  • [24] Poison Egg: Scrambling Federated Learning with Delayed Backdoor Attack
    Tsutsui, Masayoshi
    Kaneko, Tatsuya
    Takamaeda-Yamazaki, Shinya
    UBIQUITOUS SECURITY, UBISEC 2023, 2024, 2034 : 191 - 204
  • [25] Genetic Algorithm-Based Dynamic Backdoor Attack on Federated Learning-Based Network Traffic Classification
    Nazzal, Mahmoud
    Aljaafari, Nura
    Sawalmeh, Ahmed
    Khreishah, Abdallah
    Anan, Muhammad
    Algosaibi, Abdulelah
    Alnaeem, Mohammed
    Aldalbahi, Adel
    Alhumam, Abdulaziz
    Vizcarra, Conrado P.
    Alhamed, Shadan
    2023 EIGHTH INTERNATIONAL CONFERENCE ON FOG AND MOBILE EDGE COMPUTING, FMEC, 2023, : 204 - 209
  • [26] An adaptive robust defending algorithm against backdoor attacks in federated learning
    Wang, Yongkang
    Zhai, Di-Hua
    He, Yongping
    Xia, Yuanqing
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 143 : 118 - 131
  • [27] Efficient and Secure Federated Learning Against Backdoor Attacks
    Miao, Yinbin
    Xie, Rongpeng
    Li, Xinghua
    Liu, Zhiquan
    Choo, Kim-Kwang Raymond
    Deng, Robert H.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 4619 - 4636
  • [28] FederatedReverse: A Detection and Defense Method Against Backdoor Attacks in Federated Learning
    Zhao, Chen
    Wen, Yu
    Li, Shuailou
    Liu, Fucheng
    Meng, Dan
    PROCEEDINGS OF THE 2021 ACM WORKSHOP ON INFORMATION HIDING AND MULTIMEDIA SECURITY, IH&MMSEC 2021, 2021, : 51 - 62
  • [29] LR-BA: Backdoor attack against vertical federated learning using local latent representations
    Gu, Yuhao
    Bai, Yuebin
    COMPUTERS & SECURITY, 2023, 129
  • [30] Sample-independent federated learning backdoor attack in speaker recognition
    Weida Xu
    Yang Xu
    Sicong Zhang
    Cluster Computing, 2025, 28 (3)