Distributed Swift and Stealthy Backdoor Attack on Federated Learning

dc.contributor.authorSundar, Agnideven Palanisamy
dc.contributor.authorLi, Feng
dc.contributor.departmentComputer and Information Science, School of Science
dc.date.accessioned2024-01-16T19:41:50Z
dc.date.available2024-01-16T19:41:50Z
dc.date.issued2022-10-01
dc.description.abstractFederated Learning (FL) provides enhanced privacy over traditional centralized learning; unfortunately, it is also as susceptible to backdoor attacks, just like its centralized counterpart. Conventionally, in data poisoning-based backdoor attacks, all the malicious participants overlay the same single trigger pattern on a subset of their private data during local training. The same trigger is used to induce the backdoor in the otherwise benign global model at inference time. Such single trigger attacks can be detected and removed with relative ease as they undermine the distributed nature of FL. In this work, we focus on building an attack scheme where each batch of malicious clients uses sizably discrete local triggers during local training, with the ability to invoke the attack with a single small inference trigger during the global model testing. The larger size of the trigger pattern ensures prolonged attack longevity even after the termination of the attack. We conduct extensive experiments to show that our approach is far faster, stealthier, and more effective than the centralized trigger approach. The stealthiness of our work is explained using the DeepLIFT visual feature interpretation method.
dc.eprint.versionAuthor's manuscript
dc.identifier.citationSundar, A. P., & Li, F. (2022). Distributed Swift and Stealthy Backdoor Attack on Federated Learning. The 16th IEEE International Conference on Networking, Architecture, and Storage (NAS’22), 1-8. https://par.nsf.gov/biblio/10358817-distributed-swift-stealthy-backdoor-attack-federated-learning
dc.identifier.urihttps://hdl.handle.net/1805/38019
dc.language.isoen_US
dc.publisherIEEE
dc.relation.journal16th IEEE International Conference on Networking, Architecture, and Storage (NAS’22)
dc.rightsPublisher Policy
dc.sourceAuthor
dc.subjectFederated Learning (FL)
dc.subjecttrigger attacks
dc.subjectsingle small inference trigger
dc.subjectDeepLIFT
dc.titleDistributed Swift and Stealthy Backdoor Attack on Federated Learning
dc.typeArticle
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Sundar2022Distributed-NSFAAM.pdf
Size:
2.92 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.99 KB
Format:
Item-specific license agreed upon to submission
Description: