Distributed Cumulative Gradient Backdoor Attack Against Federated Learning
摘要
In this paper, for the problem of covert backdoor attack initiated by malicious clients in the federated learning system, we propose a distributed accumulated gradient backdoor attack DABGA framework. By designing a momentum-accelerated gradient difference propagation mechanism, it constructs cross-round attack direction consistency, and utilize a distributed collaborative triggering architecture to achieve covert aggregation of local attack loads; combined with an adaptive dynamic regulation strategy, it balances the strength of backdoor implantation with the covertness of gradient update. To address the shortcomings of traditional attack methods in persistence and covertness, we integrate the historical gradient decay factor and real-time feedback mechanism to ensure that the malicious updates are always located in the legitimate gradient distribution area. In this paper, we design a series of experiments to simulate the DABGA attack under different scenarios and evaluate the effectiveness of existing attack and defense strategies in dealing with this attack. The experiments show that DABGA can effectively pose a covert threat to the federated learning system in the scenario where 20% malicious clients are involved, and that there are limitations in the existing defense mechanisms to defend against such attacks.