With the rapid development of Internet of Things (IoT) technology, Human Activity Recognition (HAR) has seen increasingly widespread applications in daily life, such as in health monitoring and activity tracking features commonly found in smartphones and smartwatches. However, despite the significant advancements in preserving user privacy through federated learning, numerous challenges remain, particularly in terms of security. During the training process in federated learning, the data on participating client devices is not visible to the server, making the system vulnerable to attacks by malicious clients. Specifically, a malicious client may use backdoor-infused data to train its local model, which can then compromise the global model when the server aggregates these models. To the best of our knowledge, no existing research has addressed the issue of backdoor attacks in Federated Human Activity Recognition. To address this gap, we propose an effective method for generating HAR backdoor data based on observations from public datasets. Experimental results indicate that our backdoor attack method achieves excellent attack success rates across six public HAR datasets. Our work offers new insights and potential solutions for enhancing the security of HAR models in federated learning.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

BadHAR: Backdoor Attacks in Federated Human Activity Recognition Systems

  • Dongping Zhang,
  • Bing Mi,
  • Kongyang Chen

摘要

With the rapid development of Internet of Things (IoT) technology, Human Activity Recognition (HAR) has seen increasingly widespread applications in daily life, such as in health monitoring and activity tracking features commonly found in smartphones and smartwatches. However, despite the significant advancements in preserving user privacy through federated learning, numerous challenges remain, particularly in terms of security. During the training process in federated learning, the data on participating client devices is not visible to the server, making the system vulnerable to attacks by malicious clients. Specifically, a malicious client may use backdoor-infused data to train its local model, which can then compromise the global model when the server aggregates these models. To the best of our knowledge, no existing research has addressed the issue of backdoor attacks in Federated Human Activity Recognition. To address this gap, we propose an effective method for generating HAR backdoor data based on observations from public datasets. Experimental results indicate that our backdoor attack method achieves excellent attack success rates across six public HAR datasets. Our work offers new insights and potential solutions for enhancing the security of HAR models in federated learning.