Backdoor Attack is a Devil in Federated GAN-Based Medical Image Synthesis

被引:3
|
作者
Jin, Ruinan [1 ]
Li, Xiaoxiao [1 ]
机构
[1] Univ British Columbia, Vancouver, BC, Canada
来源
SIMULATION AND SYNTHESIS IN MEDICAL IMAGING, SASHIMI 2022 | 2022年 / 13570卷
基金
加拿大自然科学与工程研究理事会;
关键词
GAN; Federated learning; Backdoor attack;
D O I
10.1007/978-3-031-16980-9_15
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep Learning-based image synthesis techniques have been applied in healthcare research for generating medical images to support open research. Training generative adversarial neural networks (GAN) usually requires large amounts of training data. Federated learning (FL) provides a way of training a central model using distributed data from different medical institutions while keeping raw data locally. However, FL is vulnerable to backdoor attack, an adversarial by poisoning training data, given the central server cannot access the original data directly. Most backdoor attack strategies focus on classification models and centralized domains. In this study, we propose a way of attacking federated GAN (FedGAN) by treating the discriminator with a commonly used data poisoning strategy in backdoor attack classification models. We demonstrate that adding a small trigger with size less than 0.5% of the original image size can corrupt the FedGAN model. Based on the proposed attack, we provide two effective defense strategies: global malicious detection and local training regularization. We show that combining the two defense strategies yields a robust medical image generation.
引用
收藏
页码:154 / 165
页数:12
相关论文
共 50 条
  • [21] SlaugFL: Efficient Edge Federated Learning With Selective GAN-Based Data Augmentation
    Liu, Jianqi
    Zhao, Zhiwei
    Luo, Xiangyang
    Li, Pan
    Min, Geyong
    Li, Huiyong
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2024, 23 (12) : 11191 - 11208
  • [22] Backdoor Attack Based on Lossy Image Compression Using Discrete Cosine Transform
    Liu, Yuting
    Gu, Hong
    Zhang, Annan
    Qin, Pan
    IEEE ACCESS, 2024, 12 : 196488 - 196497
  • [23] Backdoor Attack on Unpaired Medical Image-Text Foundation Models: A Pilot Study on MedCLIP
    Jin, Ruinan
    Huang, Chun-Yin
    You, Chenyu
    Li, Xiaoxiao
    IEEE CONFERENCE ON SAFE AND TRUSTWORTHY MACHINE LEARNING, SATML 2024, 2024, : 272 - 285
  • [24] Federated Medical Image Analysis with Virtual Sample Synthesis
    Zhu, Wei
    Luo, Jiebo
    MEDICAL IMAGE COMPUTING AND COMPUTER ASSISTED INTERVENTION, MICCAI 2022, PT III, 2022, 13433 : 728 - 738
  • [25] GANFed: GAN-based Federated Learning with Non-IID Datasets in Edge IoTs
    Fan, Xin
    Wang, Yue
    Zhang, Weishan
    Li, Yingshu
    Cai, Zhipeng
    Tian, Zhi
    ICC 2024 - IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2024, : 5443 - 5448
  • [26] BPDGAN: A GAN-Based Unsupervised Back Project Dense Network for Multi-Modal Medical Image Fusion
    Liu, Shangwang
    Yang, Lihan
    ENTROPY, 2022, 24 (12)
  • [27] Minimal data poisoning attack in federated learning for medical image classification: An attacker perspective
    Kumar, K. Naveen
    Mohan, C. Krishna
    Cenkeramaddi, Linga Reddy
    Awasthi, Navchetan
    ARTIFICIAL INTELLIGENCE IN MEDICINE, 2025, 159
  • [28] Grey is the new RGB: How good is GAN-based image colorization for image compression?
    Fatima, Aroosh
    Hussain, Wajahat
    Rasool, Shahzad
    MULTIMEDIA TOOLS AND APPLICATIONS, 2021, 80 (03) : 3775 - 3791
  • [29] GAN-Based Image Compression Using Mutual Information for Optimizing Subjective Image Similarity
    Kudo, Shinobu
    Orihashi, Shota
    Tanida, Ryuichi
    Takamura, Seishi
    Kimata, Hideaki
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2021, E104D (03) : 450 - 460
  • [30] Grey is the new RGB: How good is GAN-based image colorization for image compression?
    Aroosh Fatima
    Wajahat Hussain
    Shahzad Rasool
    Multimedia Tools and Applications, 2021, 80 : 3775 - 3791