Invariant Aggregator for Defending against Federated Backdoor Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Xiaoyang, Dimitriadis, Dimitrios, Koyejo, Sanmi, Tople, Shruti
Format: Preprint
Published: 2022
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909132807733248
author Wang, Xiaoyang
Dimitriadis, Dimitrios
Koyejo, Sanmi
Tople, Shruti
author_facet Wang, Xiaoyang
Dimitriadis, Dimitrios
Koyejo, Sanmi
Tople, Shruti
contents Federated learning enables training high-utility models across several clients without directly sharing their private data. As a downside, the federated setting makes the model vulnerable to various adversarial attacks in the presence of malicious clients. Despite the theoretical and empirical success in defending against attacks that aim to degrade models' utility, defense against backdoor attacks that increase model accuracy on backdoor samples exclusively without hurting the utility on other samples remains challenging. To this end, we first analyze the failure modes of existing defenses over a flat loss landscape, which is common for well-designed neural networks such as Resnet (He et al., 2015) but is often overlooked by previous works. Then, we propose an invariant aggregator that redirects the aggregated update to invariant directions that are generally useful via selectively masking out the update elements that favor few and possibly malicious clients. Theoretical results suggest that our approach provably mitigates backdoor attacks and remains effective over flat loss landscapes. Empirical results on three datasets with different modalities and varying numbers of clients further demonstrate that our approach mitigates a broad class of backdoor attacks with a negligible cost on the model utility.
format Preprint
id arxiv_https___arxiv_org_abs_2210_01834
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Invariant Aggregator for Defending against Federated Backdoor Attacks
Wang, Xiaoyang
Dimitriadis, Dimitrios
Koyejo, Sanmi
Tople, Shruti
Machine Learning
Cryptography and Security
Federated learning enables training high-utility models across several clients without directly sharing their private data. As a downside, the federated setting makes the model vulnerable to various adversarial attacks in the presence of malicious clients. Despite the theoretical and empirical success in defending against attacks that aim to degrade models' utility, defense against backdoor attacks that increase model accuracy on backdoor samples exclusively without hurting the utility on other samples remains challenging. To this end, we first analyze the failure modes of existing defenses over a flat loss landscape, which is common for well-designed neural networks such as Resnet (He et al., 2015) but is often overlooked by previous works. Then, we propose an invariant aggregator that redirects the aggregated update to invariant directions that are generally useful via selectively masking out the update elements that favor few and possibly malicious clients. Theoretical results suggest that our approach provably mitigates backdoor attacks and remains effective over flat loss landscapes. Empirical results on three datasets with different modalities and varying numbers of clients further demonstrate that our approach mitigates a broad class of backdoor attacks with a negligible cost on the model utility.
title Invariant Aggregator for Defending against Federated Backdoor Attacks
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2210.01834