Defending against Backdoors in Federated Learning with Robust Learning Rate

后门 计算机科学 对手 计算机安全 集合(抽象数据类型) 对抗制 方案(数学) 人工智能 数学 数学分析 程序设计语言
作者
Mustafa Safa Özdayi,Murat Kantarcıoğlu,Yulia R. Gel
出处
期刊:Proceedings of the ... AAAI Conference on Artificial Intelligence [Association for the Advancement of Artificial Intelligence (AAAI)]
卷期号:35 (10): 9268-9276 被引量:60
标识
DOI:10.1609/aaai.v35i10.17118
摘要

Federated learning (FL) allows a set of agents to collaboratively train a model without sharing their potentially sensitive data. This makes FL suitable for privacy-preserving applications. At the same time, FL is susceptible to adversarial attacks due to decentralized and unvetted data. One important line of attacks against FL is the backdoor attacks. In a backdoor attack, an adversary tries to embed a backdoor functionality to the model during training that can later be activated to cause a desired misclassification. To prevent backdoor attacks, we propose a lightweight defense that requires minimal change to the FL protocol. At a high level, our defense is based on carefully adjusting the aggregation server's learning rate, per dimension and per round, based on the sign information of agents' updates. We first conjecture the necessary steps to carry a successful backdoor attack in FL setting, and then, explicitly formulate the defense based on our conjecture. Through experiments, we provide empirical evidence that supports our conjecture, and we test our defense against backdoor attacks under different settings. We observe that either backdoor is completely eliminated, or its accuracy is significantly reduced. Overall, our experiments suggest that our defense significantly outperforms some of the recently proposed defenses in the literature. We achieve this by having minimal influence over the accuracy of the trained models. In addition, we also provide convergence rate analysis for our proposed scheme.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
1秒前
鱼浅溪发布了新的文献求助10
1秒前
dennisysz发布了新的文献求助10
1秒前
KK关注了科研通微信公众号
1秒前
ghy发布了新的文献求助10
2秒前
fhg完成签到 ,获得积分10
2秒前
3秒前
3秒前
3秒前
3秒前
3秒前
3秒前
赘婿应助满意的柏柳采纳,获得10
4秒前
朱123发布了新的文献求助10
4秒前
4秒前
4秒前
4秒前
gougoudy完成签到,获得积分10
5秒前
花花发布了新的文献求助10
5秒前
5秒前
无极微光应助科研通管家采纳,获得20
5秒前
乐乐应助科研通管家采纳,获得10
5秒前
pluto应助科研通管家采纳,获得10
5秒前
bkagyin应助科研通管家采纳,获得10
5秒前
杨华启应助科研通管家采纳,获得10
5秒前
泊远轩应助科研通管家采纳,获得10
5秒前
慕青应助科研通管家采纳,获得10
5秒前
脑洞疼应助科研通管家采纳,获得10
5秒前
6秒前
6秒前
打打应助科研通管家采纳,获得10
6秒前
bkagyin应助科研通管家采纳,获得10
6秒前
6秒前
Akim应助科研通管家采纳,获得10
6秒前
泊远轩应助科研通管家采纳,获得10
6秒前
CipherSage应助科研通管家采纳,获得10
6秒前
酷波er应助科研通管家采纳,获得10
6秒前
6秒前
6秒前
汉堡包应助blUe采纳,获得10
7秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
No Good Deed Goes Unpunished 1100
Bioseparations Science and Engineering Third Edition 1000
Lloyd's Register of Shipping's Approach to the Control of Incidents of Brittle Fracture in Ship Structures 1000
BRITTLE FRACTURE IN WELDED SHIPS 1000
Entre Praga y Madrid: los contactos checoslovaco-españoles (1948-1977) 1000
Polymorphism and polytypism in crystals 1000
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 纳米技术 有机化学 物理 生物化学 化学工程 计算机科学 复合材料 内科学 催化作用 光电子学 物理化学 电极 冶金 遗传学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 6100081
求助须知:如何正确求助?哪些是违规求助? 7929785
关于积分的说明 16424600
捐赠科研通 5229821
什么是DOI,文献DOI怎么找? 2794979
邀请新用户注册赠送积分活动 1777336
关于科研通互助平台的介绍 1651103