Defense against backdoor attack in federated learning

被引:20
|
作者
Lu, Shiwei [1 ]
Li, Ruihu [1 ]
Liu, Wenbin [2 ]
Chen, Xuan [1 ]
机构
[1] Air Force Engn Univ, Fundamentals Dept, Xian 710077, Peoples R China
[2] Guangzhou Univ, Inst Adv Computat Sci & Technol, Guangzhou 510006, Guangdong, Peoples R China
基金
中国国家自然科学基金;
关键词
Federated learning; Model replacement attack; Adaptive backdoor attack; Model similarity measurement; Backdoor neuron activation; Abnormal model detection;
D O I
10.1016/j.cose.2022.102819
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a new distributed machine learning framework, Federated Learning (FL) effectively solves the problems of data silo and privacy protection in the field of artificial intelligence. However, for its independent devices, heterogeneous data and unbalanced data distribution, it is more vulnerable to adversarial attack, especially backdoor attack. In this paper, we investigate typical backdoor attacks in FL, containing model replacement attack and adaptive backdoor attack. Based on attack initiating round, we divide backdoor attack into convergence-round attack and early-round attack. In addition, we respectively design a defense scheme with model pre-aggregation and similarity measurement to detect and remove backdoor model under convergence-round attack and a defense scheme with backdoor neuron activation to remove backdoor under early-round attack. Experiments and performance analysis show that compared to benchmark schemes, our defense scheme with similarity measurement obtains the highest backdoor detection accuracy under model replacement attack (25% increase) and adaptive backdoor attack (67% increase) at the convergence round. Moreover, detection effect is the most stable. Compared to defense of participant-level differential privacy and adversarial training, our defense scheme with backdoor neuron activation can rapidly remove malicious effects of backdoor without reducing the main task accuracy under early-round attack. Thus, the robustness of FL can be improved greatly with our defense schemes. We make our key codes public at Github https://github.com/lsw3130104597/Backdoor_detection. (C) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:11
相关论文
共 50 条
  • [31] Poison Egg: Scrambling Federated Learning with Delayed Backdoor Attack
    Tsutsui, Masayoshi
    Kaneko, Tatsuya
    Takamaeda-Yamazaki, Shinya
    UBIQUITOUS SECURITY, UBISEC 2023, 2024, 2034 : 191 - 204
  • [32] Lockdown: Backdoor Defense for Federated Learning with Isolated Subspace Training
    Huang, Tiansheng
    Hu, Sihao
    Chow, Ka-Ho
    Ilhan, Fatih
    Tekin, Selim Furkan
    Liu, Ling
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [33] Beyond Traditional Threats: A Persistent Backdoor Attack on Federated Learning
    Liu, Tao
    Zhang, Yuhang
    Feng, Zhu
    Yang, Zhiqin
    Xu, Chen
    Man, Dapeng
    Yang, Wu
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 19, 2024, : 21359 - 21367
  • [34] Backdoor defense method in federated learning based on contrastive training
    Zhang J.
    Zhu C.
    Cheng X.
    Sun X.
    Chen B.
    Tongxin Xuebao/Journal on Communications, 45 (03): : 182 - 196
  • [35] Efficient and Secure Federated Learning Against Backdoor Attacks
    Miao, Yinbin
    Xie, Rongpeng
    Li, Xinghua
    Liu, Zhiquan
    Choo, Kim-Kwang Raymond
    Deng, Robert H.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 4619 - 4636
  • [36] LFGurad: A Defense against Label Flipping Attack in Federated Learning for Vehicular Network
    Sameera, K. M.
    Vinod, P.
    Rehiman, K. A. Rafidha
    Conti, Mauro
    COMPUTER NETWORKS, 2024, 254
  • [37] Securing federated learning: a defense strategy against targeted data poisoning attack
    Ansam Khraisat
    Ammar Alazab
    Moutaz Alazab
    Tony Jan
    Sarabjot Singh
    Md. Ashraf Uddin
    Discover Internet of Things, 5 (1):
  • [38] LR-BA: Backdoor attack against vertical federated learning using local latent representations
    Gu, Yuhao
    Bai, Yuebin
    COMPUTERS & SECURITY, 2023, 129
  • [39] Sample-independent federated learning backdoor attack in speaker recognition
    Weida Xu
    Yang Xu
    Sicong Zhang
    Cluster Computing, 2025, 28 (3)
  • [40] Mitigating Distributed Backdoor Attack in Federated Learning Through Mode Connectivity
    Walter, Kane
    Mohammady, Meisam
    Nepal, Surya
    Kanhere, Salil S.
    PROCEEDINGS OF THE 19TH ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ACM ASIACCS 2024, 2024, : 1287 - 1298