GAN-inspired Defense Against Backdoor Attack on Federated Learning Systems

dc.contributor.authorSundar, Agnideven Palanisamy
dc.contributor.authorLi, Feng
dc.contributor.authorZou, Xukai
dc.contributor.authorGao, Tianchong
dc.contributor.authorHosler, Ryan
dc.contributor.departmentComputer Science, Luddy School of Informatics, Computing, and Engineering
dc.date.accessioned2025-03-28T19:56:47Z
dc.date.available2025-03-28T19:56:47Z
dc.date.issued2023-09
dc.description.abstractFederated Learning (FL) provides an opportunity for clients with limited data resources to combine and build better Machine Learning models without compromising their privacy. But aggregating contributions from various clients implies that the errors present in some clients’ resources will also get propagated to all the clients through the combined model. Malicious entities leverage this negative factor to disrupt the normal functioning of the FL system for their gain. A backdoor attack is one such attack where the malicious entities act as clients and implant a small trigger into the global model. Once implanted, the model performs the attacker desired task in the presence of the trigger but acts benignly otherwise. In this paper, we build a GAN-inspired defense mechanism that can detect and defend against the presence of such backdoor triggers. The unavailability of labeled benign and backdoored models has prevented researchers from building detection classifiers. We tackle this problem by utilizing the clients as Generators to construct the required dataset. We place the Discriminator on the server-side, which acts as a backdoored model detecting binary classifier. We experimentally prove the proficiency of our approach with the image-based non-IID datasets, CIFAR10 and CelebA. Our prediction probability-based defense mechanism successfully removes all the influence of backdoors from the global model.
dc.eprint.versionAuthor's manuscript
dc.identifier.citationSundar, A. P., Li, F., Zou, X., Gao, T., & Hosler, R. (2023). GAN-inspired Defense Against Backdoor Attack on Federated Learning Systems. 2023 IEEE 20th International Conference on Mobile Ad Hoc and Smart Systems (MASS), 452–460. https://doi.org/10.1109/MASS58611.2023.00063
dc.identifier.urihttps://hdl.handle.net/1805/46649
dc.language.isoen
dc.publisherIEEE
dc.relation.isversionof10.1109/MASS58611.2023.00063
dc.relation.journal2023 IEEE 20th International Conference on Mobile Ad Hoc and Smart Systems (MASS)
dc.rightsPublisher Policy
dc.sourceAuthor
dc.subjectfederated learning
dc.subjectGAN-inspired defense mechanism
dc.subjectbackdoor triggers
dc.titleGAN-inspired Defense Against Backdoor Attack on Federated Learning Systems
dc.typeArticle
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Zou2023GAN-inspired-AAM.pdf
Size:
433.83 KB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
2.04 KB
Format:
Item-specific license agreed upon to submission
Description: