Perception Poisoning Attacks in Federated Learning

被引:10
|
作者
Chow, Ka-Ho [1 ]
Liu, Ling [1 ]
机构
[1] Georgia Inst Technol, Sch Comp Sci, Atlanta, GA 30332 USA
来源
2021 THIRD IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2021) | 2021年
基金
美国国家科学基金会;
关键词
federated learning; object detection; data poisoning; deep neural networks; DEFENSES;
D O I
10.1109/TPSISA52974.2021.00017
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning (FL) enables decentralized training of deep neural networks (DNNs) for object detection over a distributed population of clients. It allows edge clients to keep their data local and only share parameter updates with a federated server. However, the distributed nature of FL also opens doors to new threats. In this paper, we present targeted perception poisoning attacks against federated object detection learning in which a subset of malicious clients seeks to poison the federated training of a global object detection model by sharing perception-poisoned local model parameters. We first introduce three targeted perception poisoning attacks, which have severe adverse effects only on the objects under attack. We then analyze the attack feasibility, the impact of malicious client availability, and attack timing. To safeguard FL systems against such contagious threats, we introduce spatial signature analysis as a defense to separate benign local model parameters from poisoned local model contributions, identify malicious clients, and eliminate their impact on the federated training. Extensive experiments on object detection benchmark datasets validate that the defense-empowered federated object detection learning can improve the robustness against all three types of perception poisoning attacks. The source code is available at https://github.com/git-disl/Perception-Poisoning.
引用
收藏
页码:146 / 155
页数:10
相关论文
共 50 条
  • [31] Defending against Poisoning Backdoor Attacks on Federated Meta-learning
    Chen, Chien-Lun
    Babakniya, Sara
    Paolieri, Marco
    Golubchik, Leana
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2022, 13 (05)
  • [32] DeMAC: Towards detecting model poisoning attacks in federated learning system
    Yang, Han
    Gu, Dongbing
    He, Jianhua
    INTERNET OF THINGS, 2023, 23
  • [33] Evaluating Security and Robustness for Split Federated Learning Against Poisoning Attacks
    Wu, Xiaodong
    Yuan, Henry
    Li, Xiangman
    Ni, Jianbing
    Lu, Rongxing
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 175 - 190
  • [34] FEDCLEAN: A DEFENSE MECHANISM AGAINST PARAMETER POISONING ATTACKS IN FEDERATED LEARNING
    Kumar, Abhishek
    Khimani, Vivek
    Chatzopoulos, Dimitris
    Hui, Pan
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 4333 - 4337
  • [35] Poisoning Attacks on Federated Learning-based Wireless Traffic Prediction
    Zhang, Zifan
    Fang, Minghong
    Huang, Jiayuan
    Liu, Yuchen
    2024 23RD IFIP NETWORKING CONFERENCE, IFIP NETWORKING 2024, 2024, : 423 - 431
  • [36] Defense Strategies Toward Model Poisoning Attacks in Federated Learning: A Survey
    Wang, Zhilin
    Kang, Qiao
    Zhang, Xinyi
    Hu, Qin
    2022 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE (WCNC), 2022, : 548 - 553
  • [37] Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning
    Shejwalkar, Virat
    Houmansadr, Amir
    28TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2021), 2021,
  • [38] Precision Guided Approach to Mitigate Data Poisoning Attacks in Federated Learning
    Kumar, K. Naveen
    Mohan, C. Krishna
    Machiry, Aravind
    PROCEEDINGS OF THE FOURTEENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, CODASPY 2024, 2024, : 233 - 244
  • [39] DUPS: Data poisoning attacks with uncertain sample selection for federated learning
    Zhang, Heng-Ru
    Wang, Ke-Xiong
    Liang, Xiang-Yu
    Yu, Yi-Fan
    COMPUTER NETWORKS, 2025, 256
  • [40] Securing Federated Learning: Enhancing Defense Mechanisms against Poisoning Attacks
    Birdman, Benjamin
    Thamilarasu, Geethapriya
    2024 33RD INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, ICCCN 2024, 2024,