arrow
Return

Optimally Mitigating Backdoor Attacks in Federated Learning

delete2024-07-01
delete0
PRE
AI
K
Kane Walter *
M
Meisam Mohammady
‪Surya Nepal‬
S
Salil S. Kanhere
DOI:10.1109/TDSC.2023.3320694delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Federated learning (FL) is a distributed, privacy-preserving learning paradigm where a joint model is trained on private data stored on client devices. Data owners (clients) train models locally and then submit them to an aggregation server for incorporation into the joint model. Malicious clients can apply training time attacks, e.g., backdoor attacks, by submitting maliciously trained models. Prior work has shown that Differential Privacy (DP) can provide certified robustness to backdoor attacks; however, there are limited studies regarding DP parameter selection as a function of the model architecture. In this work, we show empirically that larger models (i.e., with more parameters) require stronger DP parameter settings to mitigate backdoor attacks. Furthermore, we present a framework that alters the FL training algorithm to preserve certified accuracy round-by-round and show empirically that it is superior to a model trainer selecting DP parameters ahead of time before training begins and with incomplete information about the attacker. Although tools from DP are used in our proposed framework, it is focused on backdoor attack mitigation and does not provide privacy guarantees.
Keywords:
Backdoor attack
differential privacy
federated learning
Backdoor attack
differential privacy
federated learning

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.4K
Citations:
9.6K

Organization

I
Iowa State University
Scholars:
2.1W
Papers: 1.8W
Citations: 2.5W