A Dynamic Optimization Scheme Based Backdoor Attack DPBA in Federated Learning

Chenchen Yang, Huawei Zhao · 2024

Federated Learning (FL) is a distributed machine learning approach that enables participants to federally train a global model without disclosing private information. However, FL’s dispersed nature and direct access to data introduce new security issues, especially backdoor attacks. In this case, the attacker injects the backdoor into the global model during training while maintaining the accuracy of the global model, to affect the classification results for only a small number of data points. Although some backdoor attack models are currently having some success, these successes are based on less realistic assumptions, such as the need for the attacker to be in control of a sufficient number of clients or to know the data distribution of otherwise honest clients. In addition, in many cases, injected backdoor triggers are often visually easy to detect. If backdoor triggers are removed from the training process, the backdoor effect is quickly diluted. How to address the stealthy and persistent nature of backdoor attacks is a long-standing and urgent problem. To solve these problems, we propose a new dynamic backdoor attack method DPBA in FL. DPBA approximates the prediction of future dynamic updates of the global model by a global model based on the forgotten backdoor, which first learns a backdoor generation trigger model, then optimizes that trigger with the predicted global model, and finally injects the generated backdoor into the global model to poison it. The dynamic prediction produced by this optimization method allows the generated model to be closer to the real one, i.e., it can reduce the distance between the poisonous and normal models, which allows for better stealth and extending the backdoor’s existence. Finally, we assess the proposed attack model on numerous benchmark datasets (which include MNIST, CIFAR-10, and Tiny ImageNet). The results show that we proposed the attack model can bypass existing mainstream backdoor defenses, obtain a high attack success rate, and achieve a more persistent backdoor effect than other backdoor attacks.

Read the paper · More papers on PaperTik