Breaking Distributed Backdoor Defenses for Federated Learning in Non-IID Settings

Jijia Yang, Jiangang Shu*, Xiaohua Jia

*Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

2 Citations (Scopus)

Abstract

Federated learning (FL) is a privacy-preserving distributed machine learning architecture to solve the problem of data silos. While FL is proposed to protect data security, it still faces security challenges. Backdoor attacks are potential threats in FL and aim to manipulate the model performance on chosen backdoor tasks by injecting adversarial triggers. As a more insidious variant of backdoor attacks, distributed backdoor attacks decompose the same global trigger into multiple local patterns and respectively assign them to different attackers. In this paper, we study deep into the entire training process of current distributed backdoor attack (DBA) and propose a cooperative DBA method for non-IID FL to break through existing defenses. To bypass the cosine similarity detection, we design an update rotation and scaling technique based on two independent training to well disguise malicious updates among benign updates. We conduct an exhaustive experiment to evaluate the performance of our proposed method under the state-of-the-art defenses. The experimental results show that it is much more stealthy than the current DBA method while maintaining the high backdoor attack intensity. © 2022 IEEE.
Original languageEnglish
Title of host publicationProceedings - 2022 18th International Conference on Mobility, Sensing and Networking (MSN 2022)
PublisherIEEE
Pages347-354
ISBN (Electronic)978-1-6654-6457-4
DOIs
Publication statusPublished - Dec 2022
Event18th International Conference on Mobility, Sensing and Networking (MSN 2022) - Virtual, Online, China
Duration: 14 Dec 202216 Dec 2022
Conference number: 18
https://ieee-msn.org/2022/index.php
https://ieeexplore.ieee.org/xpl/conhome/10076543/proceeding

Publication series

NameProceedings - International Conference on Mobility, Sensing and Networking, MSN

Conference

Conference18th International Conference on Mobility, Sensing and Networking (MSN 2022)
Abbreviated titleMSN
Country/TerritoryChina
CityVirtual, Online
Period14/12/2216/12/22
Internet address

Research Keywords

  • cosine similarity
  • distributed backdoor attack
  • federated learning
  • rotation and scaling

Fingerprint

Dive into the research topics of 'Breaking Distributed Backdoor Defenses for Federated Learning in Non-IID Settings'. Together they form a unique fingerprint.

Cite this