Fed-NAD: Backdoor Resilient Federated Learning via Neural Attention Distillation

被引:0
|
作者
Ma, Hao [1 ]
Qi, Senmao [1 ]
Yao, Jiayue [1 ]
Yuan, Yuan [1 ]
Zou, Yifei [1 ]
Yu, Dongxiao [1 ]
机构
[1] Shandong Univ, Sch Comp Sci & Technol, Qingdao, Peoples R China
基金
中国国家自然科学基金;
关键词
Federated Learning; Backdoor Attack; Neural Attention Distillation;
D O I
10.1109/IDS62739.2024.00009
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning (FL) has emerged as a distributed machine learning paradigm with applications across various domains, offering the ability to train a global model across multiple devices while preserving data privacy. However, the distributed nature of FL also introduces backdoor vulnerabilities, where malicious participants can cooperatively poison the global model by meticulously scaling their shared models. In this paper, we propose Fed-NAD, a backdoor-resilient FL framework. Specifically, Fed-NAD leverages neural attention distillation to enable benign clients to effectively purify the backdoored global model during local training. Through a two-stage process, benign clients first train a teacher network locally on clean datasets to capture benign input features, which is then used to perform neural attention distillation on the aggregated backdoored global model. This process ensures that benign clients can cooperatively obtain clean global models without backdoors. Extensive experiments conducted on the CIFAR-10 dataset utilizing ResNet-18 architecture showcase the efficacy and resilience of Fed-NAD, constituting a significant contribution to the domain of FL security. Numerical results demonstrate a notable decrease in attack success rates, ranging from 30% to 60%, while incurring no more than a 2% reduction in accuracy compared to other defense baselines.
引用
收藏
页码:7 / 13
页数:7
相关论文
共 50 条
  • [1] BadCleaner: Defending Backdoor Attacks in Federated Learning via Attention-Based Multi-Teacher Distillation
    Zhang, Jiale
    Zhu, Chengcheng
    Ge, Chunpeng
    Ma, Chuan
    Zhao, Yanchao
    Sun, Xiaobing
    Chen, Bing
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 4559 - 4573
  • [2] FMDL: Federated Mutual Distillation Learning for Defending Backdoor Attacks
    Sun, Hanqi
    Zhu, Wanquan
    Sun, Ziyu
    Cao, Mingsheng
    Liu, Wenbin
    [J]. ELECTRONICS, 2023, 12 (23)
  • [3] Knowledge Distillation Based Defense for Audio Trigger Backdoor in Federated Learning
    Chen, Yu-Wen
    Ke, Bo-Hsu
    Chen, Bo-Zhong
    Chiu, Si-Rong
    Tu, Chun-Wei
    Kuo, Jian-Jhih
    [J]. IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 4271 - 4276
  • [4] FLEDGE: Ledger-based Federated Learning Resilient to Inference and Backdoor Attacks
    Castillo, Jorge
    Rieger, Phillip
    Fereidooni, Hossein
    Chen, Qian
    Sadeghi, Ahmad-Reza
    [J]. 39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 647 - 661
  • [5] Identifying Backdoor Attacks in Federated Learning via Anomaly Detection
    Mi, Yuxi
    Sun, Yiheng
    Guan, Jihong
    Zhou, Shuigeng
    [J]. WEB AND BIG DATA, PT III, APWEB-WAIM 2023, 2024, 14333 : 111 - 126
  • [6] BaFFLe: Backdoor Detection via Feedback -based Federated Learning
    Andreina, Sebastien
    Marson, Giorgia Azzurra
    Moellering, Helen
    Karame, Ghassan
    [J]. 2021 IEEE 41ST INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2021), 2021, : 852 - 863
  • [7] NBA: defensive distillation for backdoor removal via neural behavior alignment
    Ying, Zonghao
    Wu, Bin
    [J]. CYBERSECURITY, 2023, 6 (01)
  • [8] NBA: defensive distillation for backdoor removal via neural behavior alignment
    Zonghao Ying
    Bin Wu
    [J]. Cybersecurity, 6
  • [9] FLPurifier: Backdoor Defense in Federated Learning via Decoupled Contrastive Training
    Zhang, Jiale
    Zhu, Chengcheng
    Sun, Xiaobing
    Ge, Chunpeng
    Chen, Bing
    Susilo, Willy
    Yu, Shui
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 4752 - 4766
  • [10] Ensemble Attention Distillation for Privacy-Preserving Federated Learning
    Gong, Xuan
    Sharma, Abhishek
    Karanam, Srikrishna
    Wu, Ziyan
    Chen, Terrence
    Doermann, David
    Innanje, Arun
    [J]. 2021 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV 2021), 2021, : 15056 - 15066