Towards training time attacks for federated machine learning systems
Ji Feng, Qi-Zhi Cai, Yuan Jiang · Scientia Sinica Informationis · 2021
Federated machine learning systems have gained more and more attention and popularity in both academia and industry because they can obtain a shared model among multiple parties without explicitly sharing the training data. Such a system is believed to have a good potential of protecting data privacy compared with the traditional machine learning frameworks. On the other hand, training time attacks are a procedure of purposefully modifying training data, hoping to manipulate the behavior of the corresponding trained system during test time. DeepConfuse, for instance, is one recent advance in generating adversarial training data with high efficiency. In this work, we extend the DeepConfuse framework so that it can be used in federated machine learning. This is the first training time attack for a federated learning system. The empirical results showed that the federated learning system is even more vulnerable under the DeepConfuse attack in terms of $\delta$-accuracy loss.