DUPS: Data poisoning attacks with uncertain sample selection for federated learning

被引:1
作者
Zhang, Heng-Ru [1 ]
Wang, Ke-Xiong
Liang, Xiang-Yu
Yu, Yi-Fan
机构
[1] Southwest Petr Univ, Sch Comp Sci & Software Engn, Chengdu 610500, Peoples R China
基金
中国国家自然科学基金;
关键词
Federated learning; Poisoning attacks; Sampling; Uncertain samples;
D O I
10.1016/j.comnet.2024.110909
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The server in federated learning maintains a global model by aggregating local updates from trusted clients. Poisoning attacks against federated learning influence the global model by manipulating local updates. Existing works typically employ two strategies for the controlled clients: local data modification or local update manipulation. In this paper, we propose DUPS: Data Poisoning attacks with Uncertain Sample selection that does not directly alter the data or local update of the controlled clients. The main concept is to sample from rather than synthesize by or alter the original data for use in training poisoning updates. First, samples with the target label of the controlled clients are classified using the local model. Samples with the label that has the highest number of misclassifications are selected as uncertain ones. Second, these samples are extracted individually to train poisoned updates. Finally, all controlled clients upload these poisoned updates to the server. Experiments are carried out on five datasets in comparison to five state-of-the-art algorithms. Results show that the proposed attack can effectively improve the poisoning mission rate.
引用
收藏
页数:11
相关论文
共 44 条
[1]  
Anguita D, 2013, ESANN, V3, P3
[2]  
Asuncion A., 2007, UCI machine learning repository
[3]  
Bagdasaryan E, 2020, PR MACH LEARN RES, V108, P2938
[4]   The security of machine learning [J].
Barreno, Marco ;
Nelson, Blaine ;
Joseph, Anthony D. ;
Tygar, J. D. .
MACHINE LEARNING, 2010, 81 (02) :121-148
[5]  
Biggio B., 2012, P 29 INT COF INT C M, P1467, DOI 10.48550/arxiv.1206.6389
[6]   Cryptographic Accelerators for Digital Signature Based on Ed25519 [J].
Bisheh-Niasar, Mojtaba ;
Azarderakhsh, Reza ;
Mozaffari-Kermani, Mehran .
IEEE TRANSACTIONS ON VERY LARGE SCALE INTEGRATION (VLSI) SYSTEMS, 2021, 29 (07) :1297-1305
[7]  
Blanchard P, 2017, ADV NEUR IN, V30
[8]  
Bonawitz K, 2019, Arxiv, DOI arXiv:1902.01046
[9]  
Cao XY, 2022, Arxiv, DOI [arXiv:2012.13995, DOI 10.48550/ARXIV.2012.13995]
[10]   MPAF: Model Poisoning Attacks to Federated Learning based on Fake Clients [J].
Cao, Xiaoyu ;
Gong, Neil Zhenqiang .
2022 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION WORKSHOPS, CVPRW 2022, 2022, :3395-3403