Robust Federated Learning for Ubiquitous Computing through Mitigation of Edge-Case Backdoor Attacks

Author:

Elhattab Fatima1ORCID,Bouchenak Sara1ORCID,Talbi Rania1ORCID,Nitu Vlad2ORCID

Affiliation:

1. INSA Lyon - LIRIS, Lyon, France

2. CNRS - LIRIS, Lyon, France

Abstract

Federated Learning (FL) allows several data owners to train a joint model without sharing their training data. Such a paradigm is useful for better privacy in many ubiquitous computing systems. However, FL is vulnerable to poisoning attacks, where malicious participants attempt to inject a backdoor task in the model at training time, along with the main task that the model was initially trained for. Recent works show that FL is particularly vulnerable to edge-case backdoors introduced by data points with unusual out-of-distribution features. Such attacks are among the most difficult to counter, and today's FL defense mechanisms usually fail to tackle them. In this paper, we present ARMOR, a defense mechanism that leverages adversarial learning to uncover edge-case backdoors. In contrast to most of existing FL defenses, ARMOR does not require real data samples and is compatible with secure aggregation, thus, providing better FL privacy protection. ARMOR relies on GANs (Generative Adversarial Networks) to extract data features from model updates, and uses the generated samples to test the activation of potential edge-case backdoors in the model. Our experimental evaluations with three widely used datasets and neural networks show that ARMOR can tackle edge-case backdoors with 95% resilience against attacks, and without hurting model quality.

Publisher

Association for Computing Machinery (ACM)

Subject

Computer Networks and Communications,Hardware and Architecture,Human-Computer Interaction

Reference52 articles.

1. BaFFLe: Backdoor Detection via Feedback-based Federated Learning

2. Manoj Ghuhan Arivazhagan , Vinay Aggarwal , Aaditya Kumar Singh, and Sunav Choudhary . 2019 . Federated Learning with Personalization Layers . arXiv:1912.00818 1912.00818 (2019). http://arxiv.org/abs/1912.00818 Manoj Ghuhan Arivazhagan, Vinay Aggarwal, Aaditya Kumar Singh, and Sunav Choudhary. 2019. Federated Learning with Personalization Layers. arXiv:1912.00818 1912.00818 (2019). http://arxiv.org/abs/1912.00818

3. Eugene Bagdasaryan , Andreas Veit , Yiqing Hua , Deborah Estrin , and Vitaly Shmatikov . 2020 . How To Backdoor Federated Learning. In The 23rd International Conference on Artificial Intelligence and Statistics, AISTATS 2020, 26--28 August 2020, Online [Palermo, Sicily, Italy] R@(Proceedings of Machine Learning Research , Vol. 108), Silvia Chiappa and Roberto Calandra (Eds.). PMLR, Palermo, Sicily, Italy, 2938-- 2948 . http://proceedings.mlr.press/v108/bagdasaryan20a.html Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How To Backdoor Federated Learning. In The 23rd International Conference on Artificial Intelligence and Statistics, AISTATS 2020, 26--28 August 2020, Online [Palermo, Sicily, Italy] R@(Proceedings of Machine Learning Research, Vol. 108), Silvia Chiappa and Roberto Calandra (Eds.). PMLR, Palermo, Sicily, Italy, 2938--2948. http://proceedings.mlr.press/v108/bagdasaryan20a.html

4. Learning ECOC Code Matrix for Multiclass Classification with Application to Glaucoma Diagnosis

Cited by 4 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Web 3.0 security: Backdoor attacks in federated learning-based automatic speaker verification systems in the 6G era;Future Generation Computer Systems;2024-11

2. Unfair Trojan: Targeted Backdoor Attacks Against Model Fairness;Springer Optimization and Its Applications;2024-05-10

3. Data and Model Poisoning Backdoor Attacks on Wireless Federated Learning, and the Defense Mechanisms: A Comprehensive Survey;IEEE Communications Surveys & Tutorials;2024

4. Towards Scalable Resilient Federated Learning: A Fully Decentralised Approach;2023 IEEE International Conference on Pervasive Computing and Communications Workshops and other Affiliated Events (PerCom Workshops);2023-03-13

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3