FLAME: Taming Backdoors in Federated Learning (Extended Version 1)

后门 计算机科学 对手 噪音(视频) 过程(计算) 聚类分析 机器学习 人工智能 入侵检测系统 差别隐私 数据挖掘 计算机安全 图像(数学) 操作系统
作者
Thien Duc Nguyen,Phillip Rieger,Huili Chen,Hossein Yalame,Helen Möllering,Hossein Fereidooni,Samuel Marchal,Markus Miettinen,Azalia Mirhoseini,Shaza Zeitouni,Farinaz Koushanfar,Ahmad‐Reza Sadeghi,Thomas Schneider
出处
期刊:Cornell University - arXiv [Cornell University]
标识
DOI:10.48550/arxiv.2101.02281
摘要

Federated Learning (FL) is a collaborative machine learning approach allowing participants to jointly train a model without having to share their private, potentially sensitive local datasets with others. Despite its benefits, FL is vulnerable to backdoor attacks, in which an adversary injects manipulated model updates into the model aggregation process so that the resulting model will provide targeted false predictions for specific adversary-chosen inputs. Proposed defenses against backdoor attacks based on detecting and filtering out malicious model updates consider only very specific and limited attacker models, whereas defenses based on differential privacy-inspired noise injection significantly deteriorate the benign performance of the aggregated model. To address these deficiencies, we introduce FLAME, a defense framework that estimates the sufficient amount of noise to be injected to ensure the elimination of backdoors while maintaining the model performance. To minimize the required amount of noise, FLAME uses a model clustering and weight clipping approach. Our evaluation of FLAME on several datasets stemming from application areas including image classification, word prediction, and IoT intrusion detection demonstrates that FLAME removes backdoors effectively with a negligible impact on the benign performance of the models. Furthermore, following the considerable attention that our research has received after its presentation at USENIX SEC 2022, FLAME has become the subject of numerous investigations proposing diverse attack methodologies in an attempt to circumvent it. As a response to these endeavors, we provide a comprehensive analysis of these attempts. Our findings show that these papers (e.g., 3DFed [36]) have not fully comprehended nor correctly employed the fundamental principles underlying FLAME, i.e., our defense mechanism effectively repels these attempted attacks.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
1秒前
酷波er应助小小怪下士采纳,获得10
1秒前
脑洞疼应助JJ采纳,获得10
1秒前
1秒前
Luhan发布了新的文献求助10
1秒前
1秒前
2秒前
2秒前
2秒前
Hedy完成签到,获得积分10
2秒前
斯文败类应助soilman采纳,获得10
2秒前
zhangxinask完成签到,获得积分10
2秒前
奋斗土豆发布了新的文献求助10
2秒前
3秒前
3秒前
3秒前
阿易完成签到,获得积分20
3秒前
小星星完成签到,获得积分10
4秒前
想飞的鱼完成签到,获得积分10
4秒前
火星上的菲鹰举报钟金男求助涉嫌违规
4秒前
小马甲应助欢迎光Ling采纳,获得10
4秒前
5秒前
dadous发布了新的文献求助10
5秒前
小魏发布了新的文献求助10
5秒前
余慵慵完成签到 ,获得积分10
6秒前
核桃发布了新的文献求助10
6秒前
儒雅颜发布了新的文献求助10
6秒前
JURIIY完成签到,获得积分10
6秒前
bkagyin应助weimz采纳,获得30
6秒前
罗春燕发布了新的文献求助10
7秒前
科研牛马发布了新的文献求助20
7秒前
7秒前
maazhu发布了新的文献求助10
7秒前
Bearbiscuit完成签到,获得积分10
7秒前
heye发布了新的文献求助10
8秒前
ye发布了新的文献求助10
8秒前
8秒前
9秒前
反复发作完成签到 ,获得积分10
9秒前
Luhan完成签到,获得积分10
9秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
2026年中国辛酸癸酸聚乙二醇甘油酯行业市场现状调查及投资机会研判报告 1000
2026年中国辛酸癸酸聚乙二醇甘油酯行业市场规模及竞争格局分析报告 1000
Resiliency Scale for Adolescents--Chinese Version 800
Fundamentals of Pharmaceutical and Biologics Regulations: A Global Perspective, Second Edition 700
作者名:Kristopher P. Plain,悉尼大学的,目前只能查到其四篇论文,想找到其博士论文 550
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7327934
求助须知:如何正确求助?哪些是违规求助? 8942850
关于积分的说明 18967640
捐赠科研通 6983859
什么是DOI,文献DOI怎么找? 3216234
关于科研通互助平台的介绍 2382982
邀请新用户注册赠送积分活动 2195671