Defending against Poisoning Backdoor Attacks on Federated Meta-learning

Defending against Poisoning Backdoor Attacks on Federated Meta-learning
复制标题

DOI:
10.1145/3523062
复制
发表时间:
2022-09
期刊:
ACM Transactions on Intelligent Systems and Technology (TIST)
影响因子:
--
通讯作者:
Chien-Lun Chen;Sara Babakniya;Marco Paolieri;L. Golubchik
Chien-Lun Chen;Sara Babakniya;Marco Paolieri;L. Golubchik
中科院分区:
其他
文献类型:
--
作者:
Chien-Lun Chen;Sara Babakniya;Marco Paolieri;L. Golubchik

文献摘要

相似文献

联邦学习允许多个用户协作训练共享分类模型,同时保护数据隐私。在这种方法中,模型更新是由中央服务器聚合的,这种方法很容易受到恶意后门攻击的攻击:恶意用户可以更改共享模型,对给定类的特定输入进行任意分类。在本文中,我们分析了后门攻击对联邦元学习的影响,在联邦元学习中,用户只使用几个示例训练一个模型,该模型可以适应不同的输出类集。虽然适应能力原则上可以使联邦学习框架对后门攻击(当新的训练示例是良性的)更加健壮,但我们发现即使是一次性攻击也可以非常成功,并且在额外的训练之后仍然存在。为了解决这些漏洞,我们提出了一种受匹配网络启发的防御机制,其中输入的类别是根据其特征与标记示例的支持集的相似性来预测的。通过从与联邦共享的模型中删除决策逻辑,后门攻击的成功率和持久性大大降低。
Federated learning allows multiple users to collaboratively train a shared classification model while preserving data privacy. This approach, where model updates are aggregated by a central server, was shown to be vulnerable to poisoning backdoor attacks: a malicious user can alter the shared model to arbitrarily classify specific inputs from a given class. In this article, we analyze the effects of backdoor attacks on federated meta-learning, where users train a model that can be adapted to different sets of output classes using only a few examples. While the ability to adapt could, in principle, make federated learning frameworks more robust to backdoor attacks (when new training examples are benign), we find that even one-shot attacks can be very successful and persist after additional training. To address these vulnerabilities, we propose a defense mechanism inspired by matching networks, where the class of an input is predicted from the similarity of its features with a support set of labeled examples. By removing the decision logic from the model shared with the federation, the success and persistence of backdoor attacks are greatly reduced.