Federated Learning (FL) is vulnerable to backdoor attacks through data poisoning if the data is not scrutinized, as malicious participants can inject backdoor triggers in normal samples, leading to poisoned updates. Distributed backdoor attacks pose a greater threat than centralized ones, as they often use fixed pixel blocks as triggers, increasing the risk of detection. This paper presents a novel distributed backdoor attack strategy that leverages edge structure poisoning to circumvent existing defense mechanisms, employing a distributed poisoning strategy to evade current defense mechanisms, thereby enhancing the stealth of the attack. Experimental results on multiple benchmark datasets demonstrate that this method is more effective and stealthy compared to other backdoor attack methods. Furthermore, this paper also proposes targeted defense strategies based on the experimental results, offering a new perspective on the security of FL systems.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Advancing Evasion: Distributed Backdoor Attacks in Federated Learning

  • Jian Wang,
  • Hong Shen,
  • Wei Ke

摘要

Federated Learning (FL) is vulnerable to backdoor attacks through data poisoning if the data is not scrutinized, as malicious participants can inject backdoor triggers in normal samples, leading to poisoned updates. Distributed backdoor attacks pose a greater threat than centralized ones, as they often use fixed pixel blocks as triggers, increasing the risk of detection. This paper presents a novel distributed backdoor attack strategy that leverages edge structure poisoning to circumvent existing defense mechanisms, employing a distributed poisoning strategy to evade current defense mechanisms, thereby enhancing the stealth of the attack. Experimental results on multiple benchmark datasets demonstrate that this method is more effective and stealthy compared to other backdoor attack methods. Furthermore, this paper also proposes targeted defense strategies based on the experimental results, offering a new perspective on the security of FL systems.