GANcrop: A Contrastive Defense Against Backdoor Attacks in Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gan, Xiaoyun, Gan, Shanyu, Su, Taizhi, Liu, Peng
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913371681456128
author Gan, Xiaoyun
Gan, Shanyu
Su, Taizhi
Liu, Peng
author_facet Gan, Xiaoyun
Gan, Shanyu
Su, Taizhi
Liu, Peng
contents With heightened awareness of data privacy protection, Federated Learning (FL) has attracted widespread attention as a privacy-preserving distributed machine learning method. However, the distributed nature of federated learning also provides opportunities for backdoor attacks, where attackers can guide the model to produce incorrect predictions without affecting the global model training process. This paper introduces a novel defense mechanism against backdoor attacks in federated learning, named GANcrop. This approach leverages contrastive learning to deeply explore the disparities between malicious and benign models for attack identification, followed by the utilization of Generative Adversarial Networks (GAN) to recover backdoor triggers and implement targeted mitigation strategies. Experimental findings demonstrate that GANcrop effectively safeguards against backdoor attacks, particularly in non-IID scenarios, while maintaining satisfactory model accuracy, showcasing its remarkable defensive efficacy and practical utility.
format Preprint
id arxiv_https___arxiv_org_abs_2405_20727
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle GANcrop: A Contrastive Defense Against Backdoor Attacks in Federated Learning
Gan, Xiaoyun
Gan, Shanyu
Su, Taizhi
Liu, Peng
Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
With heightened awareness of data privacy protection, Federated Learning (FL) has attracted widespread attention as a privacy-preserving distributed machine learning method. However, the distributed nature of federated learning also provides opportunities for backdoor attacks, where attackers can guide the model to produce incorrect predictions without affecting the global model training process. This paper introduces a novel defense mechanism against backdoor attacks in federated learning, named GANcrop. This approach leverages contrastive learning to deeply explore the disparities between malicious and benign models for attack identification, followed by the utilization of Generative Adversarial Networks (GAN) to recover backdoor triggers and implement targeted mitigation strategies. Experimental findings demonstrate that GANcrop effectively safeguards against backdoor attacks, particularly in non-IID scenarios, while maintaining satisfactory model accuracy, showcasing its remarkable defensive efficacy and practical utility.
title GANcrop: A Contrastive Defense Against Backdoor Attacks in Federated Learning
topic Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2405.20727