Backdoor Attack is a Devil in Federated GAN-Based Medical Image Synthesis

被引:3
|
作者
Jin, Ruinan [1 ]
Li, Xiaoxiao [1 ]
机构
[1] Univ British Columbia, Vancouver, BC, Canada
来源
SIMULATION AND SYNTHESIS IN MEDICAL IMAGING, SASHIMI 2022 | 2022年 / 13570卷
基金
加拿大自然科学与工程研究理事会;
关键词
GAN; Federated learning; Backdoor attack;
D O I
10.1007/978-3-031-16980-9_15
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deep Learning-based image synthesis techniques have been applied in healthcare research for generating medical images to support open research. Training generative adversarial neural networks (GAN) usually requires large amounts of training data. Federated learning (FL) provides a way of training a central model using distributed data from different medical institutions while keeping raw data locally. However, FL is vulnerable to backdoor attack, an adversarial by poisoning training data, given the central server cannot access the original data directly. Most backdoor attack strategies focus on classification models and centralized domains. In this study, we propose a way of attacking federated GAN (FedGAN) by treating the discriminator with a commonly used data poisoning strategy in backdoor attack classification models. We demonstrate that adding a small trigger with size less than 0.5% of the original image size can corrupt the FedGAN model. Based on the proposed attack, we provide two effective defense strategies: global malicious detection and local training regularization. We show that combining the two defense strategies yields a robust medical image generation.
引用
收藏
页码:154 / 165
页数:12
相关论文
共 50 条
  • [31] GAN-based Image Compression Using Mutual Information Maximizing Regularization
    Kudo, Shinobu
    Orihashi, Shota
    Tanida, Ryuichi
    Shimizu, Atsushi
    2019 PICTURE CODING SYMPOSIUM (PCS), 2019,
  • [32] Real-Time GAN-Based Model for Underwater Image Enhancement
    Avola, Danilo
    Cannistraci, Irene
    Cascio, Marco
    Cinque, Luigi
    Diko, Anxhelo
    Distante, Damiano
    Foresti, Gian Luca
    Mecca, Alessio
    Scagnetto, Ivan
    IMAGE ANALYSIS AND PROCESSING, ICIAP 2023, PT I, 2023, 14233 : 412 - 423
  • [33] GAN-Based Image Deblurring Using DCT Loss With Customized Datasets
    Tomosada, Hiroki
    Kudo, Takahiro
    Fujisawa, Takanori
    Ikehara, Masaaki
    IEEE ACCESS, 2021, 9 : 135224 - 135233
  • [34] Perceptual Similarity-Based Multi-Objective Optimization for Stealthy Image Backdoor Attack
    Zhu S.
    Wang J.
    Sun G.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2024, 61 (05): : 1182 - 1192
  • [35] A Privacy-Aware and Incremental Defense Method Against GAN-Based Poisoning Attack
    Qiao, Feifei
    Li, Zhong
    Kong, Yubo
    IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2024, 11 (02) : 1708 - 1721
  • [36] Leveraging Statistical Shape Priors in GAN-Based ECG Synthesis
    Neifar, Nour
    Ben-Hamadou, Achraf
    Mdhaffar, Afef
    Jmaiel, Mohamed
    Freisleben, Bernd
    IEEE ACCESS, 2024, 12 : 36002 - 36015
  • [37] JenGAN: Stacked Shifted Filters in GAN-Based Speech Synthesis
    Cho, Hyunjae
    Lee, Junhyeok
    Jung, Wonbin
    INTERSPEECH 2024, 2024, : 3879 - 3883
  • [38] Backdoor attacks-resilient aggregation based on Robust Filtering of Outliers in federated learning for image classification
    Rodriguez-Barroso, Nuria
    Martinez-Camara, Eugenio
    Luzon, M. Victoria
    Herrera, Francisco
    KNOWLEDGE-BASED SYSTEMS, 2022, 245
  • [39] Controlled synthesis of GaN-based nanowires for photoelectrochemical water splitting applications
    Ebaid, Mohamed
    Kang, Jin-Ho
    Ryu, Sang-Wan
    SEMICONDUCTOR SCIENCE AND TECHNOLOGY, 2017, 32 (01)
  • [40] Shared DNN Model Ownership Verification in Cross-Silo Federated Learning: A GAN-Based Watermark Approach
    Yan, Miao
    Su, Zhou
    Wang, Yuntao
    Ran, Xiandong
    Liu, Yiliang
    Luan, Tom H.
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 1807 - 1811