An Investigation of Recent Backdoor Attacks and Defenses in Federated Learning

Qiuxian Chen, Yizheng Tao · 2023

Federated learning (FL) is a promising paradigm for training machine learning models across distributed datasets while preserving data privacy. But it is still vulnerable to various security risks, including backdoor attacks. Backdoor attacks manifest when adversaries introduce subtle modifications to the training process, resulting in models demonstrating abnormal outputs when triggered by particular inputs. The objective of this study is to provide a comprehensive overview of the most recent advancements in both backdoor attacks and defenses within the FL context. In terms of backdoor attacks, we provide two taxonomies that are based on triggers and attack methodologies, respectively, and subdivide various attack schemes within each taxonomy. In terms of backdoor defenses, we divide the defense measures into three main categories: detection, backdoor mitigation, and robust training, and then present the technical details supporting each category. Beyond investigating current literature, our study highlights significant avenues for future research on backdoor attack and defense strategies to further enhance the security and privacy of FL systems.

Read the paper · More papers on PaperTik