Facilitating Early-Stage Backdoor Attacks in Federated Learning With Whole Population Distribution Inference

Facilitating Early-Stage Backdoor Attacks in Federated Learning With Whole Population Distribution Inference
复制标题

DOI:
10.1109/jiot.2023.3237806
复制
发表时间:
2023-06
影响因子:
10.6
通讯作者:
Tian Liu;Xueyang Hu;Tao Shu
Tian Liu;Xueyang Hu;Tao Shu
中科院分区:
计算机科学1区
文献类型:
--
作者:
Tian Liu;Xueyang Hu;Tao Shu

文献摘要

相似文献

物联网(IoT)的发展与联邦学习(FL)的出现相结合,使得移动的边缘计算(MEC)能够从物理上分离的数据中获得洞察力,而不会侵犯隐私或增加通信负担。由于MEC设备的分布式特性,研究人员发现FL容易受到后门攻击,后门攻击的目的是在不破坏主任务性能的情况下将子任务注入FL。当在FL模型收敛时注入时,后门攻击在主任务和后门子任务上都实现了高精度。然而,在早期训练阶段注入后门的有效性较弱。在本文中,我们加强了早期注入后门攻击,利用信息泄漏。我们表明,FL收敛可以加快,如果客户端的数据集模仿整个人口的分布和梯度。基于这一观察,我们提出了一个两阶段的后门攻击,其中包括后续后门攻击的初步阶段。利用初始阶段的优势,后期注入的后门实现了更好的效果,因为后门效应不太可能被正常的模型更新所稀释。在各种数据异质性设置下对MNIST数据集进行了广泛的实验,以评估所提出的后门攻击的有效性。结果表明,提出的后门优于现有的后门攻击的成功率和寿命,即使在防御机制到位。
The development of the Internet of Things (IoT) combined with the emergence of federated learning (FL) makes it possible for mobile edge computing (MEC) to gain insight from physically separated data without violating privacy or burdening communication. Due to the distributed nature of MEC devices, researchers have uncovered that the FL is vulnerable to backdoor attacks, which aim at injecting a subtask into the FL without corrupting the performance of the main task. The backdoor attack achieves high accuracy on both the main task and the backdoor subtask when injected at FL model convergence. However, the effectiveness of the backdoor is weak when injected in early training stage. In this article, we strengthen the early-injected backdoor attack by using information leakage. We show that FL convergence can be expedited if the client’s data set mimics the distribution and gradients of the whole population. Based on this observation, we propose a two-phase backdoor attack, which includes a preliminary phase for the subsequent backdoor attack. Taking advantage of the preliminary phase, the later injected backdoor achieves better effectiveness, as the backdoor effect is less likely to be diluted by normal model updates. Extensive experiments are conducted on the MNIST data set under various data heterogeneity settings to evaluate the effectiveness of the proposed backdoor attack. The results show that the proposed backdoor outperforms existing backdoor attacks in both success rate and longevity, even when defense mechanisms are in place.