Covert and Persistent Backdoor Attacks in Federated Learning-Powerd Autonomous Driving

Zhaoyuan Wang, Fan Yang, Luyao Peng, Jun Song · 2024

Federated learning (FL) is a distributed machine learning approach that helps autonomous vehicles train models together without a single organization holding all the data. FL ensures data confidentiality, but it also introduces vulnerabilities to backdoor attacks in autonomous driving systems. These attacks pose a specific threat to the accuracy of traffic sign recognition, potentially leading to the misclassification of signs and subsequent traffic accidents. To overcome these challenges, we propose a novel framework for backdoor attacks called Covert and Persistent Backdoor Attacks (CPBA), designed specifically for traffic sign recognition in autonomous driving systems. This framework utilizes a Generative Adversarial Network (GAN) to generate specific covert triggers for each sample. Minimizing the differences in feature vectors ensures that the backdoored images retain visual similarity to the original ones, making them nearly indistinguishable from human observers. Furthermore, CPBA addresses the dynamic nature of autonomous driving systems by selectively targeting model parameters that are infrequently updated and more stable, ensuring sustained effectiveness of the backdoor despite fluctuations in compromised vehicle participation and the influence of benign updates. Experimental evaluations demonstrate that CPBA maintains robustness against five distinct defense mechanisms on two publicly accessible traffic sign recognition datasets.

Read the paper · More papers on PaperTik