Perception Poisoning Attacks in Federated Learning

被引:10
|
作者
Chow, Ka-Ho [1 ]
Liu, Ling [1 ]
机构
[1] Georgia Inst Technol, Sch Comp Sci, Atlanta, GA 30332 USA
来源
2021 THIRD IEEE INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS AND APPLICATIONS (TPS-ISA 2021) | 2021年
基金
美国国家科学基金会;
关键词
federated learning; object detection; data poisoning; deep neural networks; DEFENSES;
D O I
10.1109/TPSISA52974.2021.00017
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning (FL) enables decentralized training of deep neural networks (DNNs) for object detection over a distributed population of clients. It allows edge clients to keep their data local and only share parameter updates with a federated server. However, the distributed nature of FL also opens doors to new threats. In this paper, we present targeted perception poisoning attacks against federated object detection learning in which a subset of malicious clients seeks to poison the federated training of a global object detection model by sharing perception-poisoned local model parameters. We first introduce three targeted perception poisoning attacks, which have severe adverse effects only on the objects under attack. We then analyze the attack feasibility, the impact of malicious client availability, and attack timing. To safeguard FL systems against such contagious threats, we introduce spatial signature analysis as a defense to separate benign local model parameters from poisoned local model contributions, identify malicious clients, and eliminate their impact on the federated training. Extensive experiments on object detection benchmark datasets validate that the defense-empowered federated object detection learning can improve the robustness against all three types of perception poisoning attacks. The source code is available at https://github.com/git-disl/Perception-Poisoning.
引用
收藏
页码:146 / 155
页数:10
相关论文
共 50 条
  • [41] Confident Federated Learning to Tackle Label Flipped Data Poisoning Attacks
    Ovi, Pretom Roy
    Gangopadhyay, Aryya
    Erbacher, Robert F.
    Busart, Carl
    ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING FOR MULTI-DOMAIN OPERATIONS APPLICATIONS V, 2023, 12538
  • [42] FedXPro: Bayesian Inference for Mitigating Poisoning Attacks in IoT Federated Learning
    Indrasiri, Pubudu L.
    Nguyen, Dinh C.
    Kashyap, Bipasha
    Pathirana, Pubudu N.
    Eldar, Yonina C.
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (07) : 12115 - 12131
  • [43] Low dimensional secure federated learning framework against poisoning attacks
    Erdol, Eda Sena
    Ustubioglu, Beste
    Erdol, Hakan
    Ulutas, Guzin
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 158 : 183 - 199
  • [44] Dependable federated learning for IoT intrusion detection against poisoning attacks
    Yang, Run
    He, Hui
    Wang, Yulong
    Qu, Yue
    Zhang, Weizhe
    COMPUTERS & SECURITY, 2023, 132
  • [45] Parameterizing poisoning attacks in federated learning-based intrusion detection
    Merzouk, Mohamed Amine
    Cuppens, Frederic
    Boulahia-Cuppens, Nora
    Yaich, Reda
    18TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY & SECURITY, ARES 2023, 2023,
  • [46] Poisoning Attacks against Federated Learning in Load Forecasting of Smart Energy
    Qureshi, Naik Bakht Sania
    Kim, Dong-Hoon
    Lee, Jiwoo
    Lee, Eun-Kyu
    PROCEEDINGS OF THE IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2022, 2022,
  • [47] Detecting Data Poisoning Attacks in Federated Learning for Healthcare Applications Using Deep Learning
    Omran, Alaa Hamza
    Mohammed, Sahar Yousif
    Aljanabi, Mohammed
    Iraqi Journal for Computer Science and Mathematics, 2023, 4 (04): : 225 - 237
  • [48] Sine: Similarity is Not Enough for Mitigating Local Model Poisoning Attacks in Federated Learning
    Kasyap, Harsh
    Tripathy, Somanath
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 4481 - 4494
  • [49] Evaluation of Various Defense Techniques Against Targeted Poisoning Attacks in Federated Learning
    Richards, Charles
    Khemani, Sofia
    Li, Feng
    2022 IEEE 19TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2022), 2022, : 693 - 698
  • [50] RECESS Vaccine for Federated Learning: Proactive Defense Against Model Poisoning Attacks
    Yan, Haonan
    Zhang, Wenjing
    Chen, Qian
    Li, Xiaoguang
    Sun, Wenhai
    Li, Hui
    Lin, Xiaodong
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,