Backdoor attacks-resilient aggregation based on Robust Filtering of Outliers in federated learning for image classification

被引:12
|
作者
Rodriguez-Barroso, Nuria [1 ]
Martinez-Camara, Eugenio [1 ]
Luzon, M. Victoria [2 ]
Herrera, Francisco [1 ]
机构
[1] Univ Granada, Andalusian Res Inst Data Sci & Computat Intelligen, Dept Comp Sci & Artificial Intelligence, Granada, Spain
[2] Univ Granada, Andalusian Res Inst Data Sci & Computat Intelligen, Dept Software Engn, Granada, Spain
关键词
Federated Learning; Backdoor attacks; Resilient aggregation; Robust filtering of outliers; PRIVACY;
D O I
10.1016/j.knosys.2022.108588
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated Learning is a distributed machine learning paradigm vulnerable to different kind of adversarial attacks, since its distributed nature and the inaccessibility of the data by the central server. In this work, we focus on model-poisoning backdoor attacks, because they are characterized by their stealth and effectiveness. We claim that the model updates of the clients of a federated learning setting follow a Gaussian distribution, and those ones with an outlier behavior in that distribution are likely to be adversarial clients. We propose a new federated aggregation operator called Robust Filtering of one-dimensional Outliers (RFOut-1d), which works as a resilient defensive mechanism to modelpoisoning backdoor attacks. RFOut-1d is based on an univariate outlier detection method that filters out the model updates of the adversarial clients. The results on three federated image classification dataset show that RFOut-1d dissipates the impact of the backdoor attacks to almost nullifying them throughout all the learning rounds, as well as it keeps the performance of the federated learning model and it outperforms that state-of-the-art defenses against backdoor attacks. (c) 2022 Elsevier B.V. All rights reserved.
引用
收藏
页数:11
相关论文
共 50 条
  • [31] Lung Nodule CT Image Classification Based on Adaptive Aggregate Weight Federated Learning
    Jiangfeng, Shi
    Bao, Feng
    Chen Yehang
    Chen Xiangmeng
    LASER & OPTOELECTRONICS PROGRESS, 2023, 60 (22)
  • [32] Class Imbalanced Medical Image Classification Based on Semi-Supervised Federated Learning
    Liu, Wei
    Mo, Jiaqing
    Zhong, Furu
    APPLIED SCIENCES-BASEL, 2023, 13 (04):
  • [33] Investigating the Vulnerability of Federated Learning-Based Diabetic Retinopathy Grade Classification to Gradient Inversion Attacks
    Nielsen, Christopher
    Tuladhar, Anup
    Forkert, Nils D.
    OPHTHALMIC MEDICAL IMAGE ANALYSIS, OMIA 2022, 2022, 13576 : 183 - 192
  • [34] Brain programming is immune to adversarial attacks: Towards accurate and robust image classification using symbolic learning
    Ibarra-Vazquez, Gerardo
    Olague, Gustavo
    Chan-Ley, Mariana
    Puente, Cesar
    Soubervielle-Montalvo, Carlos
    SWARM AND EVOLUTIONARY COMPUTATION, 2022, 71
  • [35] Glaucoma Retinal Image Classification Based on Multichannel Gabor Filtering and Transfer Learning
    Chaabane, Mohamed
    Chehri, Abdellah
    Chaibi, Hasna
    Elrharras, Abdessamad
    Saadane, Rachid
    2023 IEEE 97TH VEHICULAR TECHNOLOGY CONFERENCE, VTC2023-SPRING, 2023,
  • [36] FDSFL: Filtering Defense Strategies toward Targeted Poisoning Attacks in IIoT-Based Federated Learning Networking System
    Xiao, Xiong
    Tang, Zhuo
    Yang, Li
    Song, Yingjie
    Tan, Jiawei
    Li, Kenli
    IEEE NETWORK, 2023, 37 (04): : 153 - 160
  • [37] FedUA: An Uncertainty-Aware Distillation-Based Federated Learning Scheme for Image Classification
    Lee, Shao-Ming
    Wu, Ja-Ling
    INFORMATION, 2023, 14 (04)
  • [38] Credit-based Differential Privacy Stochastic Model Aggregation Algorithm for Robust Federated Learning via Blockchain
    Du, Mengyao
    Zhang, Miao
    Liu, Lin
    Xu, Kai
    Yin, Quanjun
    PROCEEDINGS OF THE 52ND INTERNATIONAL CONFERENCE ON PARALLEL PROCESSING, ICPP 2023, 2023, : 452 - 461
  • [39] RVE-PFL: Robust Variational Encoder-Based Personalized Federated Learning Against Model Inversion Attacks
    Issa, Wael
    Moustafa, Nour
    Turnbull, Benjamin
    Choo, Kim-Kwang Raymond
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 3772 - 3787
  • [40] A robust approach to model-based classification based on trimming and constraintsSemi-supervised learning in presence of outliers and label noise
    Andrea Cappozzo
    Francesca Greselin
    Thomas Brendan Murphy
    Advances in Data Analysis and Classification, 2020, 14 : 327 - 354