Defense against backdoor attack in federated learning

被引:20
|
作者
Lu, Shiwei [1 ]
Li, Ruihu [1 ]
Liu, Wenbin [2 ]
Chen, Xuan [1 ]
机构
[1] Air Force Engn Univ, Fundamentals Dept, Xian 710077, Peoples R China
[2] Guangzhou Univ, Inst Adv Computat Sci & Technol, Guangzhou 510006, Guangdong, Peoples R China
基金
中国国家自然科学基金;
关键词
Federated learning; Model replacement attack; Adaptive backdoor attack; Model similarity measurement; Backdoor neuron activation; Abnormal model detection;
D O I
10.1016/j.cose.2022.102819
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As a new distributed machine learning framework, Federated Learning (FL) effectively solves the problems of data silo and privacy protection in the field of artificial intelligence. However, for its independent devices, heterogeneous data and unbalanced data distribution, it is more vulnerable to adversarial attack, especially backdoor attack. In this paper, we investigate typical backdoor attacks in FL, containing model replacement attack and adaptive backdoor attack. Based on attack initiating round, we divide backdoor attack into convergence-round attack and early-round attack. In addition, we respectively design a defense scheme with model pre-aggregation and similarity measurement to detect and remove backdoor model under convergence-round attack and a defense scheme with backdoor neuron activation to remove backdoor under early-round attack. Experiments and performance analysis show that compared to benchmark schemes, our defense scheme with similarity measurement obtains the highest backdoor detection accuracy under model replacement attack (25% increase) and adaptive backdoor attack (67% increase) at the convergence round. Moreover, detection effect is the most stable. Compared to defense of participant-level differential privacy and adversarial training, our defense scheme with backdoor neuron activation can rapidly remove malicious effects of backdoor without reducing the main task accuracy under early-round attack. Thus, the robustness of FL can be improved greatly with our defense schemes. We make our key codes public at Github https://github.com/lsw3130104597/Backdoor_detection. (C) 2022 Elsevier Ltd. All rights reserved.
引用
收藏
页数:11
相关论文
共 50 条
  • [41] FADO: A Federated Learning Attack and Defense Orchestrator
    Rodrigues, Filipe
    Simoes, Rodrigo
    Neves, Nuno
    2023 53RD ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS, DSN-W, 2023, : 141 - 148
  • [42] BDEL: A Backdoor Attack Defense Method Based on Ensemble Learning
    Xing, Zhihuan
    Lan, Yuqing
    Yu, Yin
    Cao, Yong
    Yang, Xiaoyi
    Yu, Yichun
    Yu, Dan
    PRICAI 2024: TRENDS IN ARTIFICIAL INTELLIGENCE, PT I, 2025, 15281 : 221 - 235
  • [43] Federated Learning Backdoor Attack Scheme Based on Generative Adversarial Network
    Chen D.
    Fu A.
    Zhou C.
    Chen Z.
    Fu, Anmin (fuam@njust.edu.cn); Fu, Anmin (fuam@njust.edu.cn), 1600, Science Press (58): : 2364 - 2373
  • [44] Backdoor Attack to Giant Model in Fragment-Sharing Federated Learning
    Qi, Senmao
    Ma, Hao
    Zou, Yifei
    Yuan, Yuan
    Xie, Zhenzhen
    Li, Peng
    Cheng, Xiuzhen
    BIG DATA MINING AND ANALYTICS, 2024, 7 (04): : 1084 - 1097
  • [45] VFLIP: A Backdoor Defense for Vertical Federated Learning via Identification and Purification
    Cho, Yungi
    Han, Woorim
    Yu, Miseon
    Lee, Younghan
    Bae, Ho
    Paek, Yunheung
    COMPUTER SECURITY-ESORICS 2024, PT IV, 2024, 14985 : 291 - 312
  • [46] Knowledge Distillation Based Defense for Audio Trigger Backdoor in Federated Learning
    Chen, Yu-Wen
    Ke, Bo-Hsu
    Chen, Bo-Zhong
    Chiu, Si-Rong
    Tu, Chun-Wei
    Kuo, Jian-Jhih
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 4271 - 4276
  • [47] Successive Interference Cancellation Based Defense for Trigger Backdoor in Federated Learning
    Chen, Yu-Wen
    Ke, Bo-Hsu
    Chen, Bo-Zhong
    Chiu, Si-Rong
    Tu, Chun-Wei
    Kuo, Jian-Jhih
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 26 - 32
  • [48] A Stability-Enhanced Dynamic Backdoor Defense in Federated Learning for IIoT
    Ma, Zhixuan
    Gao, Haichang
    Li, Shangwen
    Wang, Ping
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2024, 20 (11) : 12513 - 12522
  • [49] FLPurifier: Backdoor Defense in Federated Learning via Decoupled Contrastive Training
    Zhang, Jiale
    Zhu, Chengcheng
    Sun, Xiaobing
    Ge, Chunpeng
    Chen, Bing
    Susilo, Willy
    Yu, Shui
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 4752 - 4766
  • [50] Chronic Poisoning: Backdoor Attack against Split Learning
    Yu, Fangchao
    Zeng, Bo
    Zhao, Kai
    Pang, Zhi
    Wang, Lina
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 15, 2024, : 16531 - 16538