跳至主導覽 跳至搜尋 跳過主要內容

Defending Against Backdoor Attacks with Feature Activation-Based Detection and Model Recovery

研究成果: Conference contribution同行評審

摘要

The characteristics of Federated Learning (FL) make FL highly susceptible to malicious poisoning attacks from adversaries. Existing FL defense methods can detect attacks of fixed poisoning patterns, hence are lack of flexibility. Additionally, they typically remove the malicious node models upon detection, leading to a certain degree of data loss. To address these issues, we propose a novel defense method against backdoor attacks in FL systems, effectively enhancing their robustness to malicious poisoning attacks. Specifically, we introduce a malicious update detection method based on feature activation matrices. This method compares the distribution differences of updates from different clients on the same validation data and detects malicious clients based on the outlier rates of their updates. Furthermore, to mitigate the data loss caused by the removal of malicious clients, the server assesses the distance between the distribution of feature activation matrices from the client’s historical updates and the overall model distribution in the current iteration. Based on this distance, the server performs model recovery to a certain extent. Extensive experiments on two benchmark datasets demonstrate that our method accurately detects malicious clients under various state-of-the-art model poisoning attacks. Additionally, the model recovery method provides a notable improvement to the system, ensuring the robustness and performance of the FL system.

原文English
主出版物標題Proceedings - 2024 22nd International Symposium on Network Computing and Applications, NCA 2024
發行者Institute of Electrical and Electronics Engineers Inc.
頁面294-301
頁數8
ISBN(電子)9798331510183
DOIs
出版狀態Published - 2024
事件22nd International Symposium on Network Computing and Applications, NCA 2024 - Bertinoro, Italy
持續時間: 24 10月 202426 10月 2024

出版系列

名字Proceedings - 2024 22nd International Symposium on Network Computing and Applications, NCA 2024

Conference

Conference22nd International Symposium on Network Computing and Applications, NCA 2024
國家/地區Italy
城市Bertinoro
期間24/10/2426/10/24

指紋

深入研究「Defending Against Backdoor Attacks with Feature Activation-Based Detection and Model Recovery」主題。共同形成了獨特的指紋。

引用此