Distributed Swift and Stealthy Backdoor Attack on Federated Learning

Distributed Swift and Stealthy Backdoor Attack on Federated Learning
复制标题

DOI:
10.1109/nas55553.2022.9925353
复制
发表时间:
2022-10
期刊:
2022 IEEE International Conference on Networking, Architecture and Storage (NAS)
影响因子:
--
通讯作者:
A. Sundar;Feng Li;X. Zou;Tianchong Gao
A. Sundar;Feng Li;X. Zou;Tianchong Gao
中科院分区:
其他
文献类型:
--
作者:
A. Sundar;Feng Li;X. Zou;Tianchong Gao

文献摘要

相似文献

联邦学习(FL)相比传统的集中式学习提供了更强的隐私保护;然而,它也像集中式学习一样容易受到后门攻击。通常,在基于数据投毒的后门攻击中,所有恶意参与者在本地训练期间将相同的单一触发模式覆盖在其私有数据的一个子集上。在推理时,使用相同的触发模式在原本良性的全局模型中引入后门。由于这种单一触发攻击破坏了联邦学习的分布式特性,所以相对容易被检测和消除。在这项工作中,我们专注于构建一种攻击方案,其中每批恶意客户端在本地训练期间使用大量不同的本地触发模式,并且能够在全局模型测试期间使用单个小的推理触发模式来引发攻击。触发模式的较大尺寸确保了即使在攻击结束后,攻击仍能长期持续。我们进行了大量实验,结果表明我们的方法比集中式触发方法更快、更隐蔽且更有效。我们使用DeepLIFT视觉特征解释方法解释了我们工作的隐蔽性。
Federated Learning (FL) provides enhanced privacy over traditional centralized learning; unfortunately, it is also as susceptible to backdoor attacks, just like its centralized counterpart. Conventionally, in data poisoning-based backdoor attacks, all the malicious participants overlay the same single trigger pattern on a subset of their private data during local training. The same trigger is used to induce the backdoor in the otherwise benign global model at inference time. Such single trigger attacks can be detected and removed with relative ease as they undermine the distributed nature of FL. In this work, we focus on building an attack scheme where each batch of malicious clients uses sizably discrete local triggers during local training, with the ability to invoke the attack with a single small inference trigger during the global model testing. The larger size of the trigger pattern ensures prolonged attack longevity even after the termination of the attack. We conduct extensive experiments to show that our approach is far faster, stealthier, and more effective than the centralized trigger approach. The stealthiness of our work is explained using the DeepLIFT visual feature interpretation method.