arrow
返回

How to backdoor split learning

delete2023-11-01
delete4
PRE
AI
F
Fangchao Yu
L
Lina Wang *
B
Bo Zeng
K
Kai Zhao
Z
Zhi‐Feng Pang
吴畑 封面图
吴畑 (Tian Wu)
DOI:10.1016/j.neunet.2023.09.037delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Split learning, a distributed learning framework, has garnered significant attention from academic and industrial communities. In contrast to federated learning, split learning offers a more flexible architecture for participants with limited computing resources. However, the security of split learning has been questioned due to the separation of data and model control rights from usage rights. Currently, most research work focuses on inference attacks in split learning. In this paper, we first reveal the vulnerability of split learning to backdoor attacks and present two backdoor attack frameworks from both the server and client perspectives. Regarding the client-side attacker, we insert backdoor samples into the training data by utilizing the client's direct control over local data, and propose two methods for labeling backdoor samples that can be adapted to various application scenarios. Due to the server's lack of control over the client in split learning, it is infeasible for server-side attackers to inject backdoor samples into training data. Our strategy involves leveraging the server's control over the training process to shape the optimization direction of the client model, thereby enabling it to encode backdoor samples. Moreover, we introduce an auxiliary model into the attack framework to enhance the effectiveness of the backdoor attack. The auxiliary model can increase the distinction between backdoor samples and clean samples in the feature space to improve the sensitivity of the client model to backdoor samples. Extensive evaluations demonstrate the high attack accuracy of both proposed attack frameworks without causing any compromise to the performance of the main task. Our research uncovers the potential security risks and rings the alarm for the application of split learning.
Keyword:
Split learning
Backdoor attack
Shadow model
Auxiliary model

期刊

Neural Networks 封面图
Neural Networks
IF:
6.3
论文数:
8.2K
被引数:
3.0W

机构

W
wuhan university
学者数:
8.1W
论文数: 5.8W
被引数: 70
引用论文

引用论文

err
IF0
err
err0
PREAI
err
err分享
err收藏
err分享
err收藏
err分享
err收藏
err1983-01-01
err0
errOAAI
errMichiko FUCHIGAMI
err分享
err收藏
Generative Adversarial Networks An overview生成对抗网络综述
err2018-01-01
err2.4K
errOAAI
errCreswell, Antonia; White, Tom; Dumoulin, Vincent; Arulkumaran, Kai; Sengupta, Biswa; Bharath, Anil A.
err分享
err收藏
Gastric adenocarcinoma of fundic gland type arising from heterotopic gastric glands during a 19-year follow-up period
err2019-06-04
err0
errOAAI
errTakeshi Uozumi; Hideyuki Seki; Emi Matsuzono; Susumu Sogabe; Nozomu Sugai; Jun Fujita; Junichi Suzuki; Mayuko Akimoto; Mitsuru Yanai; Akira Suzuki
err分享
err收藏
Lubrication by a Smectic Liquid Crystal
err1988-01-01
err0
PREAI
errT. E. Fischer; S. Bhattacharya; R. Salher; J. L. Lauer; Y-J. Ahn
err分享
err收藏
err分享
err收藏
学者 查看更多内容