Adaptive Backdoor Attacks Against Dataset Distillation for Federated Learning

被引:0
|
作者
Chai, Ze [1 ,2 ]
Gao, Zhipeng [1 ,2 ]
Lin, Yijing [1 ,2 ]
Zhao, Chen [1 ,2 ]
Yu, Xinlei [1 ,2 ]
Xie, Zhiqiang [1 ,2 ]
机构
[1] Beijing Univ Posts & Telecommun, Beijing, Peoples R China
[2] State Key Lab Networking & Switching Technol, Beijing, Peoples R China
来源
ICC 2024 - IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS | 2024年
关键词
Backdoor Attacks; Dataset Distillation; Federated Learning;
D O I
10.1109/ICC51166.2024.10622462
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Dataset distillation is utilized to condense large datasets into smaller synthetic counterparts, effectively reducing their size while preserving their crucial characteristics. In Federated Learning (FL) scenarios, where individual devices or servers often lack substantial computational power or storage capacity, the use of dataset distillation becomes particularly advantageous for processing large volumes of data efficiently. Current research in dataset distillation for FL has primarily focused on enhancing accuracy and reducing communication complexity, but it has largely neglected the potential risk of backdoor attacks. To solve this issue, in this paper, we propose three adaptive dataset condensation based backdoor attacks against dataset distillation for FL. Adaptive attacks in dataset distillation for FL dynamically modify triggers during the training process. These triggers, embedded in the synthetic data, are designed to bypass traditional security detection. Moreover, these attacks employ self-adaptive perturbations to effectively respond to variations in the model's parameters. Experimental results show that the proposed adaptive attacks achieve at least 5.87% higher success rates, while maintaining almost the same clean test accuracy, compared to three benchmark methods.
引用
收藏
页码:4614 / 4619
页数:6
相关论文
共 50 条
  • [31] Defense against backdoor attack in federated learning
    Lu, Shiwei
    Li, Ruihu
    Liu, Wenbin
    Chen, Xuan
    COMPUTERS & SECURITY, 2022, 121
  • [32] Identifying Backdoor Attacks in Federated Learning via Anomaly Detection
    Mi, Yuxi
    Sun, Yiheng
    Guan, Jihong
    Zhou, Shuigeng
    WEB AND BIG DATA, PT III, APWEB-WAIM 2023, 2024, 14333 : 111 - 126
  • [33] CoBA: Collusive Backdoor Attacks With Optimized Trigger to Federated Learning
    Lyu, Xiaoting
    Han, Yufei
    Wang, Wei
    Liu, Jingkai
    Wang, Bin
    Chen, Kai
    Li, Yidong
    Liu, Jiqiang
    Zhang, Xiangliang
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2025, 22 (02) : 1506 - 1518
  • [34] Backdoor attacks and defenses in federated learning: Survey, challenges and future research directions
    Nguyen, Thuy Dung
    Nguyen, Tuan
    Nguyen, Phi Le
    Pham, Hieu H.
    Doan, Khoa D.
    Wong, Kok-Seng
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2024, 127
  • [35] FD-Leaks: Membership Inference Attacks Against Federated Distillation Learning
    Yang, Zilu
    Zhao, Yanchao
    Zhang, Jiale
    WEB AND BIG DATA, PT III, APWEB-WAIM 2022, 2023, 13423 : 364 - 378
  • [36] XMAM:X-raying models with a matrix to reveal backdoor attacks for federated learning
    Zhang, Jianyi
    Zhang, Fangjiao
    Jin, Qichao
    Wang, Zhiqiang
    Lin, Xiaodong
    Hei, Xiali
    DIGITAL COMMUNICATIONS AND NETWORKS, 2024, 10 (04) : 1154 - 1167
  • [37] FUBA: Federated Uncovering of Backdoor Attacks for Heterogeneous Data
    Castellon, Fabiola Espinoza
    Singh, Deepika
    Mayoue, Aurelien
    Gouy-Pailler, Cedric
    2023 5TH IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS, TPS-ISA, 2023, : 55 - 63
  • [38] SCFL: Mitigating backdoor attacks in federated learning based on SVD and clustering 
    Wang, Yongkang
    Zhai, Di-Hua
    Xia, Yuanqing
    COMPUTERS & SECURITY, 2023, 133
  • [39] Dataset Security for Machine Learning: Data Poisoning, Backdoor Attacks, and Defenses
    Goldblum, Micah
    Tsipras, Dimitris
    Xie, Chulin
    Chen, Xinyun
    Schwarzschild, Avi
    Song, Dawn
    Madry, Aleksander
    Li, Bo
    Goldstein, Tom
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2023, 45 (02) : 1563 - 1580
  • [40] CapsuleBD: A Backdoor Attack Method Against Federated Learning Under Heterogeneous Models
    Liao, Yuying
    Zhao, Xuechen
    Zhou, Bin
    Huang, Yanyi
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 4071 - 4086