Backdoor attacks-resilient aggregation based on Robust Filtering of Outliers in federated learning for image classification

被引:12
|
作者
Rodriguez-Barroso, Nuria [1 ]
Martinez-Camara, Eugenio [1 ]
Luzon, M. Victoria [2 ]
Herrera, Francisco [1 ]
机构
[1] Univ Granada, Andalusian Res Inst Data Sci & Computat Intelligen, Dept Comp Sci & Artificial Intelligence, Granada, Spain
[2] Univ Granada, Andalusian Res Inst Data Sci & Computat Intelligen, Dept Software Engn, Granada, Spain
关键词
Federated Learning; Backdoor attacks; Resilient aggregation; Robust filtering of outliers; PRIVACY;
D O I
10.1016/j.knosys.2022.108588
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated Learning is a distributed machine learning paradigm vulnerable to different kind of adversarial attacks, since its distributed nature and the inaccessibility of the data by the central server. In this work, we focus on model-poisoning backdoor attacks, because they are characterized by their stealth and effectiveness. We claim that the model updates of the clients of a federated learning setting follow a Gaussian distribution, and those ones with an outlier behavior in that distribution are likely to be adversarial clients. We propose a new federated aggregation operator called Robust Filtering of one-dimensional Outliers (RFOut-1d), which works as a resilient defensive mechanism to modelpoisoning backdoor attacks. RFOut-1d is based on an univariate outlier detection method that filters out the model updates of the adversarial clients. The results on three federated image classification dataset show that RFOut-1d dissipates the impact of the backdoor attacks to almost nullifying them throughout all the learning rounds, as well as it keeps the performance of the federated learning model and it outperforms that state-of-the-art defenses against backdoor attacks. (c) 2022 Elsevier B.V. All rights reserved.
引用
收藏
页数:11
相关论文
共 50 条
  • [1] FLEDGE: Ledger-based Federated Learning Resilient to Inference and Backdoor Attacks
    Castillo, Jorge
    Rieger, Phillip
    Fereidooni, Hossein
    Chen, Qian
    Sadeghi, Ahmad-Reza
    [J]. 39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 647 - 661
  • [2] CRFL: Certifiably Robust Federated Learning against Backdoor Attacks
    Xie, Chulin
    Chen, Minghao
    Chen, Pin-Yu
    Li, Bo
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 139, 2021, 139
  • [3] An adaptive robust defending algorithm against backdoor attacks in federated learning
    Wang, Yongkang
    Zhai, Di-Hua
    He, Yongping
    Xia, Yuanqing
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 143 : 118 - 131
  • [4] SCFL: Mitigating backdoor attacks in federated learning based on SVD and clustering 
    Wang, Yongkang
    Zhai, Di-Hua
    Xia, Yuanqing
    [J]. COMPUTERS & SECURITY, 2023, 133
  • [5] Byzantine Robust Federated Learning Scheme Based on Backdoor Triggers
    Yang, Zheng
    Gu, Ke
    Zuo, Yiming
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2024, 79 (02): : 2813 - 2831
  • [6] Defending Federated Learning from Backdoor Attacks: Anomaly-Aware FedAVG with Layer-Based Aggregation
    Manzoor, Habib Ullah
    Khan, Ahsan Raza
    Sher, Tahir
    Ahmad, Wasim
    Zoha, Ahmed
    [J]. 2023 IEEE 34TH ANNUAL INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS, PIMRC, 2023,
  • [7] Robust Federated Learning: Maximum Correntropy Aggregation Against Byzantine Attacks
    Luan, Zhirong
    Li, Wenrui
    Liu, Meiqin
    Chen, Badong
    [J]. IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2024, : 1 - 14
  • [8] Robust Federated Learning for Ubiquitous Computing through Mitigation of Edge-Case Backdoor Attacks
    Elhattab, Fatima
    Bouchenak, Sara
    Talbi, Rania
    Nitu, Vlad
    [J]. PROCEEDINGS OF THE ACM ON INTERACTIVE MOBILE WEARABLE AND UBIQUITOUS TECHNOLOGIES-IMWUT, 2022, 6 (04):
  • [9] Romoa: Robust Model Aggregation for the Resistance of Federated Learning to Model Poisoning Attacks
    Mao, Yunlong
    Yuan, Xinyu
    Zhao, Xinyang
    Zhong, Sheng
    [J]. COMPUTER SECURITY - ESORICS 2021, PT I, 2021, 12972 : 476 - 496
  • [10] A Blockchain-Based Federated-Learning Framework for Defense against Backdoor Attacks
    Li, Lu
    Qin, Jiwei
    Luo, Jintao
    [J]. ELECTRONICS, 2023, 12 (11)