Mitigating Backdoor Attacks in Federated Learning

Mitigating Backdoor Attacks in Federated Learning
复制标题

DOI:
--
复制
发表时间:
2020-10
期刊:
ArXiv
影响因子:
--
通讯作者:
Chen Wu;Xian Yang;Sencun Zhu;P. Mitra
Chen Wu;Xian Yang;Sencun Zhu;P. Mitra
中科院分区:
其他
文献类型:
--
作者:
Chen Wu;Xian Yang;Sencun Zhu;P. Mitra

文献摘要

被引文献

相似文献

恶意客户端可以在训练阶段使用恶意数据(包括后门样本)攻击联邦学习系统。折衷的全局模型将在为任务设计的验证数据集上表现良好。然而,带有后门模式的一小部分数据可能会触发模型做出错误的预测。以前,有一场军备竞赛。在联邦学习系统的服务器端训练的聚合阶段,攻击者试图隐藏攻击,防御者试图检测攻击。在这项工作中,我们提出了一种新的方法来减少训练阶段后的后门攻击。具体来说,我们设计了一种联邦修剪方法来去除网络中的冗余神经元,然后调整模型的极值权值。在分布式Fashion-MNIST上进行的实验表明,我们的方法可以将平均攻击成功率从99.7%降低到1.9%,在验证数据集上的测试精度损失5.5%。为了最小化修剪对测试精度的影响,我们可以在修剪后进行微调,攻击成功率下降到6.4%,测试精度仅损失1.7%。
Malicious clients can attack federated learning systems by using malicious data, including backdoor samples, during the training phase. The compromised global model will perform well on the validation dataset designed for the task. However, a small subset of data with backdoor patterns may trigger the model to make a wrong prediction. Previously, there was an arms race. Attackers tried to conceal attacks and defenders tried to detect attacks during the aggregation stage of training on the server-side in a federated learning system. In this work, we propose a new method to mitigate backdoor attacks after the training phase. Specifically, we designed a federated pruning method to remove redundant neurons in the network and then adjust the model's extreme weight values. Experiments conducted on distributed Fashion-MNIST have shown that our method can reduce the average attack success rate from 99.7% to 1.9% with a 5.5% loss of test accuracy on the validation dataset. To minimize the pruning influence on test accuracy, we can fine-tune after pruning, and the attack success rate drops to 6.4%, with only a 1.7% loss of test accuracy.