Supvirus: A Scenario-Oriented Feature Poisoning Attack Approach in SplitFed Learning
Yuxin Zhao, Guangyu Wu, Jiahui Hou, Xiang-Yang Li · 2023
By combining the advantages of Federated Learning (FL) and Split Learning (SL), SplitFed Learning (SFL) has become a widely applied scheme to train deep neural networks (DNNs) in distributed training scenarios with high data privacy requirements. However, SFL systems also meet severe security challenges caused by the distributed architecture, while current attacking methods mainly focusing on security vulnerabilities but neglecting the enforceability of conducting attacks. In this paper, we study the scenario-oriented feature poison attack for the first time that aims at interfering the features achieved by the distributed clients in SFL during the transmission process. Specifically, we propose a Supvirus attacker alone with a Supvirus GAN to achieve the attack. The Supvirus attacker and Supvirus GAN conduct online attacks on the transmission link without directly affecting the system software and hardware, and based on the GAN structure, it can better focus on scene changes and obtain better optimization strategies. Experiment results on an established SFL system confirm strong stealthiness, low deployment and implementation costs, and a high attack success rate of our proposed attacker and the GAN. Our approach does not require extra modifications on the clients or the server in SFL. Meanwhile, the accuracy drop by our approach achieves 57.35% at most and the drop can still reach 42.37% in situations where only a single client is attacked. The attack time requirement, attacker convergence performance, and the differences in features before and after attacks remain similar with the normal clients.