FederatedReverse: A Detection and Defense Method Against Backdoor Attacks in Federated Learning

被引:16
|
作者
Zhao, Chen [1 ,2 ]
Wen, Yu [1 ]
Li, Shuailou [1 ,2 ]
Liu, Fucheng [1 ,2 ]
Meng, Dan [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
来源
PROCEEDINGS OF THE 2021 ACM WORKSHOP ON INFORMATION HIDING AND MULTIMEDIA SECURITY, IH&MMSEC 2021 | 2021年
关键词
Federated Learning; Backdoor Attack; Privacy Protection; Artificial Intelligence Security;
D O I
10.1145/3437880.3460403
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated learning is a secure machine learning technology proposed to protect data privacy and security in machine learning model training. However, recent studies show that federated learning is vulnerable to backdoor attacks, such as model replacement attacks and distributed backdoor attacks. Most backdoor defense techniques are not appropriate for federated learning since they are based on entire data samples that cannot be hold in federated learning scenarios. The newly proposed methods for federated learning sacrifice the accuracy of models and still fail once attacks persist in many training rounds. In this paper, we propose a novel and effective detection and defense technique called FederatedReverse for federated learning. We conduct extensive experimental evaluation of our solution. The experimental results show that, compared with the existing techniques, our solution can effectively detect and defend against various backdoor attacks in federated learning, where the success rate and duration of backdoor attacks can be greatly reduced and the accuracies of trained models are almost not reduced.
引用
收藏
页码:51 / 62
页数:12
相关论文
共 50 条
  • [41] Federated learning backdoor attack detection with persistence diagram
    Ma, Zihan
    Gao, Tianchong
    COMPUTERS & SECURITY, 2024, 136
  • [42] Shadow backdoor attack: Multi-intensity backdoor attack against federated learning
    Ren, Qixian
    Zheng, Yu
    Yang, Chao
    Li, Yue
    Ma, Jianfeng
    COMPUTERS & SECURITY, 2024, 139
  • [43] A defense mechanism against label inference attacks in Vertical Federated Learning
    Arazzi, Marco
    Nicolazzo, Serena
    Nocera, Antonino
    NEUROCOMPUTING, 2025, 624
  • [44] RoseAgg: Robust Defense Against Targeted Collusion Attacks in Federated Learning
    Yang, He
    Xi, Wei
    Shen, Yuhao
    Wu, Canhui
    Zhao, Jizhong
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 2951 - 2966
  • [45] PROFL: A Privacy-Preserving Federated Learning Method with Stringent Defense Against Poisoning Attacks
    Zhong, Yisheng
    Wang, Li-Ping
    PROCEEDINGS OF THE 2024 27 TH INTERNATIONAL CONFERENCE ON COMPUTER SUPPORTED COOPERATIVE WORK IN DESIGN, CSCWD 2024, 2024, : 260 - 265
  • [46] FEDCLEAN: A DEFENSE MECHANISM AGAINST PARAMETER POISONING ATTACKS IN FEDERATED LEARNING
    Kumar, Abhishek
    Khimani, Vivek
    Chatzopoulos, Dimitris
    Hui, Pan
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 4333 - 4337
  • [47] Collusive Backdoor Attacks in Federated Learning Frameworks for IoT Systems
    Alharbi, Saier
    Guo, Yifan
    Yu, Wei
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (11): : 19694 - 19707
  • [48] BADFL: Backdoor Attack Defense in Federated Learning From Local Model Perspective
    Zhang, Haiyan
    Li, Xinghua
    Xu, Mengfan
    Liu, Ximeng
    Wu, Tong
    Weng, Jian
    Deng, Robert H.
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2024, 36 (11) : 5661 - 5674
  • [49] CapsuleBD: A Backdoor Attack Method Against Federated Learning Under Heterogeneous Models
    Liao, Yuying
    Zhao, Xuechen
    Zhou, Bin
    Huang, Yanyi
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 4071 - 4086
  • [50] BatFL: Backdoor Detection on Federated Learning in e-Health
    Xi, Binhan
    Li, Shaofeng
    Li, Jiachun
    Liu, Hui
    Liu, Hong
    Zhu, Haojin
    2021 IEEE/ACM 29TH INTERNATIONAL SYMPOSIUM ON QUALITY OF SERVICE (IWQOS), 2021,