Towards multi-party targeted model poisoning attacks against federated learning systems

被引:20
|
作者
Chen, Zheyi [1 ]
Tian, Pu [1 ]
Liao, Weixian [1 ]
Yu, Wei [1 ]
机构
[1] Towson Univ, Dept Comp & Informat Sci, Towson, MD 21252 USA
来源
HIGH-CONFIDENCE COMPUTING | 2021年 / 1卷 / 01期
关键词
Adversarial federated learning; Perfect knowledge; Limited knowledge; Boosting strategy; High-confidence computing; BIG DATA; INTERNET; THINGS; IOT;
D O I
10.1016/j.hcc.2021.100002
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The federated learning framework builds a deep learning model collaboratively by a group of connected devices via only sharing local parameter updates to the central parameter server. Nonetheless, the lack of transparency in the local data resource makes it prone to adversarial federated attacks, which have shown increasing ability to reduce learning performance. Existing research efforts either focus on the single-party attack with impractical perfect knowledge setting , limited stealthy ability or the random attack that has no control on attack effects. In this paper, we investigate a new multi-party adversarial attack with the imperfect knowledge of the target system. Controlled by an adversary, a number of compromised devices collaboratively launch targeted model poisoning attacks, intending to misclassify the targeted samples while maintaining stealthy under different de-tection strategies. Specifically, the compromised devices jointly minimize the loss function of model training in different scenarios. To overcome the update scaling problem, we develop a new boosting strategy by introducing two stealthy metrics. Via experimental results, we show that under both perfect knowledge and limited knowl-edge settings, the multi-party attack is capable of successfully evading detection strategies while guaranteeing the convergence. We also demonstrate that the learned model achieves the high accuracy on the targeted samples, which confirms the significant impact of the multi-party attack on federated learning systems.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] Detection and Mitigation of Targeted Data Poisoning Attacks in Federated Learning
    Erbil, Pinar
    Gursoy, M. Emre
    2022 IEEE INTL CONF ON DEPENDABLE, AUTONOMIC AND SECURE COMPUTING, INTL CONF ON PERVASIVE INTELLIGENCE AND COMPUTING, INTL CONF ON CLOUD AND BIG DATA COMPUTING, INTL CONF ON CYBER SCIENCE AND TECHNOLOGY CONGRESS (DASC/PICOM/CBDCOM/CYBERSCITECH), 2022, : 271 - 278
  • [22] A Robust Privacy-Preserving Federated Learning Model Against Model Poisoning Attacks
    Yazdinejad, Abbas
    Dehghantanha, Ali
    Karimipour, Hadis
    Srivastava, Gautam
    Parizi, Reza M.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6693 - 6708
  • [23] RECESS Vaccine for Federated Learning: Proactive Defense Against Model Poisoning Attacks
    Yan, Haonan
    Zhang, Wenjing
    Chen, Qian
    Li, Xiaoguang
    Sun, Wenhai
    Li, Hui
    Lin, Xiaodong
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [24] On the Analysis of Model Poisoning Attacks against Blockchain-based Federated Learning
    Olapojoye, Rukayat
    Baza, Mohamed
    Salman, Tara
    2024 IEEE 21ST CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE, CCNC, 2024, : 943 - 949
  • [25] Resilience of Wireless Ad Hoc Federated Learning against Model Poisoning Attacks
    Tezuka, Naoya
    Ochiai, Hideya
    Sun, Yuwei
    Esaki, Hiroshi
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 168 - 177
  • [26] A Robust and Efficient Federated Learning Algorithm Against Adaptive Model Poisoning Attacks
    Yang, Han
    Gu, Dongbing
    He, Jianhua
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (09): : 16289 - 16302
  • [27] A Differentially Private Federated Learning Model Against Poisoning Attacks in Edge Computing
    Zhou, Jun
    Wu, Nan
    Wang, Yisong
    Gu, Shouzhen
    Cao, Zhenfu
    Dong, Xiaolei
    Choo, Kim-Kwang Raymond
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) : 1941 - 1958
  • [28] Multi-Party Private Set Intersection in Vertical Federated Learning
    Lu, Linpeng
    Ding, Ning
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 707 - 714
  • [29] Multi-party collaborative drug discovery via federated learning
    Huang D.
    Ye X.
    Sakurai T.
    Computers in Biology and Medicine, 2024, 171
  • [30] A survey on federated learning: a perspective from multi-party computation
    Liu, Fengxia
    Zheng, Zhiming
    Shi, Yexuan
    Tong, Yongxin
    Zhang, Yi
    FRONTIERS OF COMPUTER SCIENCE, 2024, 18 (01)