A distributed bijection-backdoor-based adversarial examples defense method in federated learning
摘要
Federated learning (FL) enables the creation of a potent global model from a consortium of clients, safeguarding sensitive client data while upholding model accuracy. Nonetheless, malevolent entities can exploit vulnerabilities by introducing subtle perturbations to client-side samples, thereby executing adversarial example (AE) attacks that disrupt model predictions. To address this challenge, we present a novel distributed bijection-backdoor-based adversarial examples defense method in federated learning, termed DBBFL. An intricate bijection mechanism is transmitted from the server to the clients via a secure channel. Clients neutralize the impact of adversarial examples on model outputs while preserving the primary task’s performance. Additionally, to bolster the model’s defense capabilities within the federated learning for practical scenarios, we devise a representation enhancement technique grounded in supervised contrastive learning (CL). This method encourages the model to craft feature representations endowed with enhanced generalization ability. Through comprehensive experiments on MNIST, CIFAR-10 and CIFAR-100, our results reveal that DBBFL is superior to the state-of-art methods in reducing the attack success rate in both independent and identically distributed (IID) and the not independent and identically distributed (Non-IID) scenario. Concurrently, DBBFL can maintain the main task performance, substantiating its efficacy in countering adversarial examples in federated learning environments.