Towards multi-party targeted model poisoning attacks against federated learning systems

被引:20
|
作者
Chen, Zheyi [1 ]
Tian, Pu [1 ]
Liao, Weixian [1 ]
Yu, Wei [1 ]
机构
[1] Towson Univ, Dept Comp & Informat Sci, Towson, MD 21252 USA
来源
HIGH-CONFIDENCE COMPUTING | 2021年 / 1卷 / 01期
关键词
Adversarial federated learning; Perfect knowledge; Limited knowledge; Boosting strategy; High-confidence computing; BIG DATA; INTERNET; THINGS; IOT;
D O I
10.1016/j.hcc.2021.100002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The federated learning framework builds a deep learning model collaboratively by a group of connected devices via only sharing local parameter updates to the central parameter server. Nonetheless, the lack of transparency in the local data resource makes it prone to adversarial federated attacks, which have shown increasing ability to reduce learning performance. Existing research efforts either focus on the single-party attack with impractical perfect knowledge setting , limited stealthy ability or the random attack that has no control on attack effects. In this paper, we investigate a new multi-party adversarial attack with the imperfect knowledge of the target system. Controlled by an adversary, a number of compromised devices collaboratively launch targeted model poisoning attacks, intending to misclassify the targeted samples while maintaining stealthy under different de-tection strategies. Specifically, the compromised devices jointly minimize the loss function of model training in different scenarios. To overcome the update scaling problem, we develop a new boosting strategy by introducing two stealthy metrics. Via experimental results, we show that under both perfect knowledge and limited knowl-edge settings, the multi-party attack is capable of successfully evading detection strategies while guaranteeing the convergence. We also demonstrate that the learned model achieves the high accuracy on the targeted samples, which confirms the significant impact of the multi-party attack on federated learning systems.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] Defending Against Targeted Poisoning Attacks in Federated Learning
    Erbil, Pinar
    Gursoy, M. Emre
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 198 - 207
  • [2] Universal Multi-Party Poisoning Attacks
    Mahloujifar, Saeed
    Mahmoody, Mohammad
    Mohammed, Ameer
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 97, 2019, 97
  • [3] Moat: Model Agnostic Defense against Targeted Poisoning Attacks in Federated Learning
    Manna, Arpan
    Kasyap, Harsh
    Tripathy, Somanath
    INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2021), PT I, 2021, 12918 : 38 - 55
  • [4] Data Poisoning Attacks Against Federated Learning Systems
    Tolpegin, Vale
    Truex, Stacey
    Gursoy, Mehmet Emre
    Liu, Ling
    COMPUTER SECURITY - ESORICS 2020, PT I, 2020, 12308 : 480 - 501
  • [5] MPCFL: Towards Multi-party Computation for Secure Federated Learning Aggregation
    Kaminaga, Hiroki
    Awaysheh, Feras M.
    Alawadi, Sadi
    Kamm, Liina
    16TH IEEE/ACM INTERNATIONAL CONFERENCE ON UTILITY AND CLOUD COMPUTING, UCC 2023, 2023,
  • [6] Augmented Multi-Party Computation Against Gradient Leakage in Federated Learning
    Zhang, Chi
    Ekanut, Sotthiwat
    Zhen, Liangli
    Li, Zengxiang
    IEEE TRANSACTIONS ON BIG DATA, 2024, 10 (06) : 742 - 751
  • [7] Defending local poisoning attacks in multi-party learning via immune system
    Xie, Fei
    Gao, Yuan
    Wang, Jiongqian
    Zhao, Wei
    KNOWLEDGE-BASED SYSTEMS, 2022, 238
  • [8] Evaluation of Various Defense Techniques Against Targeted Poisoning Attacks in Federated Learning
    Richards, Charles
    Khemani, Sofia
    Li, Feng
    2022 IEEE 19TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2022), 2022, : 693 - 698
  • [9] DeMAC: Towards detecting model poisoning attacks in federated learning system
    Yang, Han
    Gu, Dongbing
    He, Jianhua
    INTERNET OF THINGS, 2023, 23
  • [10] FedCo: A Federated Learning Controller for Content Management in Multi-party Edge Systems
    Balasubramanian, Venkatraman
    Aloqaily, Moayad
    Reisslein, Martin
    30TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2021), 2021,