• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
成果搜索

author:

Zhang, H. (Zhang, H..) [1] | Li, X. (Li, X..) [2] | Xu, M. (Xu, M..) [3] | Liu, X. (Liu, X..) [4] | Wu, T. (Wu, T..) [5] | Weng, J. (Weng, J..) [6] | Deng, R.H. (Deng, R.H..) [7]

Indexed by:

Scopus

Abstract:

There is substantial attention to federated learning with its ability to train a powerful global model collaboratively while protecting data privacy. Despite its many advantages, federated learning is vulnerable to backdoor attacks, where an adversary injects malicious weights into the global model, making the global model's targeted predictions incorrect. Existing defenses based on identifying and eliminating malicious weights ignore the similarity variation of the local weights during iterations in the malicious model detection and the presence of benign weights in the malicious model during the malicious local weight elimination, resulting in a poor defense and a degradation of global model accuracy. In this paper, we defend against backdoor attacks from the perspective of local models. Firstly, a malicious model detection method based on interpretability techniques is proposed. The method appends a sampling check after clustering to identify malicious models accurately. We further design a malicious local weight elimination method based on local weight contributions. This method preserves the benign weights in the malicious model to maintain their contributions to the global model. Finally, we analyze the security of the proposed method in terms of model closeness and then verify the effectiveness of the proposed method through experiments. In comparison with existing defenses, the results show that BADFL improves the global model accuracy by 23.14% while reducing the attack success rate to 0.04% in the best case. IEEE

Keyword:

backdoor attack clustering federated learning interpretability

Community:

  • [ 1 ] [Zhang H.]State Key Laboratory of Integrated Services Networks, and the School of Cyber Engineering, Xidian University, Xi'an, China
  • [ 2 ] [Li X.]State Key Laboratory of Integrated Services Networks, and the School of Cyber Engineering, Xidian University, Xi'an, China
  • [ 3 ] [Xu M.]School of Computer Science, Shaanxi Normal University, Xi'an, China
  • [ 4 ] [Liu X.]Key Laboratory of Information Security of Network Systems, Fuzhou University, Fuzhou, China
  • [ 5 ] [Wu T.]State Key Laboratory of Integrated Services Networks, and the School of Cyber Engineering, Xidian University, Xi'an, China
  • [ 6 ] [Weng J.]college of Cyber Security, Jinan University, Guangzhou, China
  • [ 7 ] [Deng R.H.]School of Information Systems, Singapore Management University, Singapore

Reprint 's Address:

Email:

Show more details

Related Keywords:

Related Article:

Source :

IEEE Transactions on Knowledge and Data Engineering

ISSN: 1041-4347

Year: 2024

Issue: 11

Volume: 36

Page: 1-13

8 . 9 0 0

JCR@2023

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 12

Affiliated Colleges:

Online/Total:116/10046391
Address:FZU Library(No.2 Xuyuan Road, Fuzhou, Fujian, PRC Post Code:350116) Contact Us:0591-22865326
Copyright:FZU Library Technical Support:Beijing Aegean Software Co., Ltd. 闽ICP备05005463号-1