FederatedReverse: A Detection and Defense Method Against Backdoor Attacks in Federated Learning

被引:13
|
作者
Zhao, Chen [1 ,2 ]
Wen, Yu [1 ]
Li, Shuailou [1 ,2 ]
Liu, Fucheng [1 ,2 ]
Meng, Dan [1 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing, Peoples R China
关键词
Federated Learning; Backdoor Attack; Privacy Protection; Artificial Intelligence Security;
D O I
10.1145/3437880.3460403
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated learning is a secure machine learning technology proposed to protect data privacy and security in machine learning model training. However, recent studies show that federated learning is vulnerable to backdoor attacks, such as model replacement attacks and distributed backdoor attacks. Most backdoor defense techniques are not appropriate for federated learning since they are based on entire data samples that cannot be hold in federated learning scenarios. The newly proposed methods for federated learning sacrifice the accuracy of models and still fail once attacks persist in many training rounds. In this paper, we propose a novel and effective detection and defense technique called FederatedReverse for federated learning. We conduct extensive experimental evaluation of our solution. The experimental results show that, compared with the existing techniques, our solution can effectively detect and defend against various backdoor attacks in federated learning, where the success rate and duration of backdoor attacks can be greatly reduced and the accuracies of trained models are almost not reduced.
引用
收藏
页码:51 / 62
页数:12
相关论文
共 50 条
  • [41] A Four-Pronged Defense Against Byzantine Attacks in Federated Learning
    Wan, Wei
    Hu, Shengshan
    Li, Minghui
    Lu, Jianrong
    Zhang, Longling
    Zhang, Leo Yu
    Jin, Hai
    PROCEEDINGS OF THE 31ST ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2023, 2023, : 7394 - 7402
  • [42] RoseAgg: Robust Defense Against Targeted Collusion Attacks in Federated Learning
    Yang, He
    Xi, Wei
    Shen, Yuhao
    Wu, Canhui
    Zhao, Jizhong
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 2951 - 2966
  • [43] FEDCLEAN: A DEFENSE MECHANISM AGAINST PARAMETER POISONING ATTACKS IN FEDERATED LEARNING
    Kumar, Abhishek
    Khimani, Vivek
    Chatzopoulos, Dimitris
    Hui, Pan
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 4333 - 4337
  • [44] FMDL: Federated Mutual Distillation Learning for Defending Backdoor Attacks
    Sun, Hanqi
    Zhu, Wanquan
    Sun, Ziyu
    Cao, Mingsheng
    Liu, Wenbin
    ELECTRONICS, 2023, 12 (23)
  • [45] Universal adversarial backdoor attacks to fool vertical federated learning
    Chen, Peng
    Du, Xin
    Lu, Zhihui
    Chai, Hongfeng
    COMPUTERS & SECURITY, 2024, 137
  • [46] Collusive Backdoor Attacks in Federated Learning Frameworks for IoT Systems
    Alharbi, Saier
    Guo, Yifan
    Yu, Wei
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (11): : 19694 - 19707
  • [47] ACTSS: Input Detection Defense against Backdoor Attacks via Activation Subset Scanning
    Xuan, Yuexin
    Chen, Xiaojun
    Zhao, Zhendong
    Ding, Yangyang
    Lv, Jianming
    2022 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2022,
  • [48] Lockdown: Backdoor Defense for Federated Learning with Isolated Subspace Training
    Huang, Tiansheng
    Hu, Sihao
    Chow, Ka-Ho
    Ilhan, Fatih
    Tekin, Selim Furkan
    Liu, Ling
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [49] Two-phase Defense Against Poisoning Attacks on Federated Learning-based Intrusion Detection
    Lai, Yuan-Cheng
    Lin, Jheng-Yan
    Lin, Ying-Dar
    Hwang, Ren-Hung
    Lin, Po-Chin
    Wu, Hsiao-Kuang
    Chen, Chung-Kuan
    COMPUTERS & SECURITY, 2023, 129
  • [50] Survey of Backdoor Attack and Defense Algorithms Based on Federated Learning
    Liu, Jialang
    Guo, Yanming
    Lao, Mingrui
    Yu, Tianyuan
    Wu, Yulun
    Feng, Yunhao
    Wu, Jiazhuang
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2024, 61 (10): : 2607 - 2626