Dual-domain based backdoor attack against federated learning

被引:1
|
作者
Li, Guorui [1 ,2 ]
Chang, Runxing [1 ]
Wang, Ying [3 ]
Wang, Cong [1 ,2 ]
机构
[1] Northeastern Univ, Sch Comp Sci & Engn, Shenyang 110819, Peoples R China
[2] Northeastern Univ Qinhuangdao, Hebei Key Lab Marine Percept Network & Data Proc, Qinhuangdao 066004, Peoples R China
[3] Qinhuangdao Vocat & Tech Coll, Dept Informat Engn, Qinhuangdao 066100, Peoples R China
关键词
Backdoor attack; Federated learning; Frequency domain; Spatial domain; Trigger;
D O I
10.1016/j.neucom.2025.129424
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The distributed training feature and data heterogeneity in federated learning (FL) render it susceptible to various threats, in which the backdoor attack stands out as the most destructive one. By injecting malicious functionality into the global model through poisoned updates, backdoor attacks can generate attacker-desired inference results on the trigger-embedded inputs while behaving normally on other data instances. The current backdoor triggers are of significant visual features that can be easily identified by humans or computers. Meanwhile, the common model update clipping mechanism is too simple and straightforward to be recognized by various defense methods with ease. Aiming at the above shortcomings, we proposed a dual-domain based backdoor attack (DDBA) against FL in this paper. On the one hand, DDBA generates an imperceptible dual- domain trigger for any image by superimposing in its low-frequency region of the amplitude spectrum and then applying a slight spatial distortion subsequently. On the other hand, DDBA truncates the model update dynamically based on a newly designed adaptive clipping mechanism to enhance its stealthiness. Finally, we carried out extensive experiments to evaluate the attack performance and stealth performance of DDBA on four publicly available datasets. The experiment results show that DDBA has excellent attack performance in both single-shot and multiple-shot attack scenarios as well as robust stealth performance under the existing defense methods against backdoor attacks.
引用
收藏
页数:12
相关论文
共 50 条
  • [21] Sample-independent federated learning backdoor attack in speaker recognition
    Weida Xu
    Yang Xu
    Sicong Zhang
    Cluster Computing, 2025, 28 (3)
  • [22] Mitigating Distributed Backdoor Attack in Federated Learning Through Mode Connectivity
    Walter, Kane
    Mohammady, Meisam
    Nepal, Surya
    Kanhere, Salil S.
    PROCEEDINGS OF THE 19TH ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, ACM ASIACCS 2024, 2024, : 1287 - 1298
  • [23] Backdoor Attack and Defense in Asynchronous Federated Learning for Multiple Unmanned Vehicles
    Wang, Kehao
    Zhang, Hao
    2024 3RD CONFERENCE ON FULLY ACTUATED SYSTEM THEORY AND APPLICATIONS, FASTA 2024, 2024, : 843 - 847
  • [24] DAGUARD: distributed backdoor attack defense scheme under federated learning
    Yu S.
    Chen Z.
    Chen Z.
    Liu X.
    Tongxin Xuebao/Journal on Communications, 2023, 44 (05): : 110 - 122
  • [25] Backdoor Attack to Giant Model in Fragment-Sharing Federated Learning
    Qi, Senmao
    Ma, Hao
    Zou, Yifei
    Yuan, Yuan
    Xie, Zhenzhen
    Li, Peng
    Cheng, Xiuzhen
    BIG DATA MINING AND ANALYTICS, 2024, 7 (04): : 1084 - 1097
  • [26] Federated Learning Watermark Based on Model Backdoor
    Li X.
    Deng T.-P.
    Xiong J.-B.
    Jin B.
    Lin J.
    Ruan Jian Xue Bao/Journal of Software, 2024, 35 (07): : 3454 - 3468
  • [27] Chronic Poisoning: Backdoor Attack against Split Learning
    Yu, Fangchao
    Zeng, Bo
    Zhao, Kai
    Pang, Zhi
    Wang, Lina
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 15, 2024, : 16531 - 16538
  • [28] Revisiting Personalized Federated Learning: Robustness Against Backdoor Attacks
    Qin, Zeyu
    Yao, Liuyi
    Chen, Daoyuan
    Li, Yaliang
    Ding, Bolin
    Cheng, Minhao
    PROCEEDINGS OF THE 29TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2023, 2023, : 4743 - 4755
  • [29] GANcrop: A Contrastive Defense Against Backdoor Attacks in Federated Learning
    Gan, Xiaoyun
    Gan, Shanyu
    Su, Taizhi
    Liu, Peng
    2024 5TH INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKS AND INTERNET OF THINGS, CNIOT 2024, 2024, : 606 - 612
  • [30] FedPD: Defending federated prototype learning against backdoor attacks
    Tan, Zhou
    Cai, Jianping
    Li, De
    Lian, Puwei
    Liu, Ximeng
    Che, Yan
    NEURAL NETWORKS, 2025, 184