BayBFed: Bayesian Backdoor Defense for Federated Learning

BayBFed: Bayesian Backdoor Defense for Federated Learning
复制标题

DOI:
10.1109/sp46215.2023.10179362
复制
发表时间:
2023-01
期刊:
2023 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Kavita Kumari;P. Rieger;H. Fereidooni;Murtuza Jadliwala;A. Sadeghi
Kavita Kumari;P. Rieger;H. Fereidooni;Murtuza Jadliwala;A. Sadeghi
中科院分区:
其他
文献类型:
--
作者:
Kavita Kumari;P. Rieger;H. Fereidooni;Murtuza Jadliwala;A. Sadeghi

文献摘要

被引文献

相似文献

联合学习(FL)是一种新兴的技术,允许参与者在不与他人共享他们的私人数据的情况下共同训练机器学习模型。然而,FL很容易受到后门攻击等中毒攻击。因此,最近提出了各种防御措施,它们主要利用全局模型的中间状态(即,Logit)或局部模型相对于全局模型的距离(即,L2−范数)来检测FL中的恶意后门。然而,由于这些方法直接对客户端更新(或权重)进行操作,其有效性取决于客户端的数据分布或对手的攻击策略等因素。本文介绍了一种新颖的、更通用的后门防御框架BayBFed,它提出了利用客户端更新的概率分布来检测FL中的恶意更新:BayBFed计算客户端更新的概率度量来跟踪更新中的任何调整,并使用一种新的检测算法来利用这种概率度量来有效地检测和过滤恶意更新。因此,它克服了以前因直接使用客户更新而出现的缺点;然而,我们的概率衡量标准将包括当地客户培训战略的所有方面。BayBFed使用两个贝叶斯非参数(BNP)扩展:(I)根据客户的更新得出概率度量的分层Beta-Bernoulli过程,以及(Ii)中式餐厅过程(CRP)的改编,我们称之为CRP-Jensen,它利用此概率度量来检测和过滤恶意更新。我们在CIFAR10、Reddit、IoT入侵检测、MNIST和FMNIST五个基准数据集上对我们的防御方法进行了广泛的评估,结果表明,它可以在不影响全局模型的良性性能的情况下,有效地检测和消除FL中的恶意更新。
Federated learning (FL) is an emerging technology that allows participants to jointly train a machine learning model without sharing their private data with others. However, FL is vulnerable to poisoning attacks such as backdoor attacks. Consequently, a variety of defenses have recently been proposed, which have primarily utilized intermediary states of the global model (i.e., logits) or distance of the local models (i.e., L2−norm) with respect to the global model to detect malicious backdoors in FL. However, as these approaches directly operate on client updates (or weights), their effectiveness depends on factors such as clients’ data distribution or the adversary’s attack strategies. In this paper, we introduce a novel and more generic backdoor defense framework, called BayBFed, which proposes to utilize probability distributions over client updates to detect malicious updates in FL: BayBFed computes a probabilistic measure over the clients’ updates to keep track of any adjustments made in the updates, and uses a novel detection algorithm that can leverage this probabilistic measure to efficiently detect and filter out malicious updates. Thus, it overcomes the shortcomings of previous approaches that arise due to the direct usage of client updates; nevertheless, our probabilistic measure will include all aspects of the local client training strategies. BayBFed utilizes two Bayesian NonParametric (BNP) extensions: (i) a Hierarchical Beta-Bernoulli process to draw a probabilistic measure given the clients’ updates, and (ii) an adaptation of the Chinese Restaurant Process (CRP), referred by us as CRP-Jensen, which leverages this probabilistic measure to detect and filter out malicious updates. We extensively evaluate our defense approach on five benchmark datasets: CIFAR10, Reddit, IoT intrusion detection, MNIST, and FMNIST, and show that it can effectively detect and eliminate malicious updates in FL without deteriorating the benign performance of the global model.