Poisoning Attack in Federated Learning Using Normalizing Flows
Huajie Hu, Yuan Liang · 2023
Federated learning can effectively solve the “isolated data island” problem but is vulnerable to poisoning attacks, mainly including backdoor attack and label-flipping attack. The backdoor attack needs to modify the input samples, which is impractical. The label-flipping attack is simple, and there is still room for improvement in the attack effect. Therefore, we propose a method to generate poisoned samples for the targeted attack using normalizing flows (SniperFlow) and apply it in the poisoning attacks in federated learning (NFPA). To the best of our knowledge, this is the first work that explores the use of normalizing flows in the poisoning Attack in federated learning. And the experiments prove that our method has outstanding attack performance, better than the label-flipping attack at the accuracy of the target task.