Client-Side Patching against Backdoor Attacks in Federated Learning

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteur principal: Molina-Coronado, Borja
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866909435643822080
author Molina-Coronado, Borja
author_facet Molina-Coronado, Borja
contents Federated learning is a versatile framework for training models in decentralized environments. However, the trust placed in clients makes federated learning vulnerable to backdoor attacks launched by malicious participants. While many defenses have been proposed, they often fail short when facing heterogeneous data distributions among participating clients. In this paper, we propose a novel defense mechanism for federated learning systems designed to mitigate backdoor attacks on the clients-side. Our approach leverages adversarial learning techniques and model patching to neutralize the impact of backdoor attacks. Through extensive experiments on the MNIST and Fashion-MNIST datasets, we demonstrate that our defense effectively reduces backdoor accuracy, outperforming existing state-of-the-art defenses, such as LFighter, FLAME, and RoseAgg, in i.i.d. and non-i.i.d. scenarios, while maintaining competitive or superior accuracy on clean data.
format Preprint
id arxiv_https___arxiv_org_abs_2412_10605
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Client-Side Patching against Backdoor Attacks in Federated Learning
Molina-Coronado, Borja
Cryptography and Security
Artificial Intelligence
Machine Learning
Federated learning is a versatile framework for training models in decentralized environments. However, the trust placed in clients makes federated learning vulnerable to backdoor attacks launched by malicious participants. While many defenses have been proposed, they often fail short when facing heterogeneous data distributions among participating clients. In this paper, we propose a novel defense mechanism for federated learning systems designed to mitigate backdoor attacks on the clients-side. Our approach leverages adversarial learning techniques and model patching to neutralize the impact of backdoor attacks. Through extensive experiments on the MNIST and Fashion-MNIST datasets, we demonstrate that our defense effectively reduces backdoor accuracy, outperforming existing state-of-the-art defenses, such as LFighter, FLAME, and RoseAgg, in i.i.d. and non-i.i.d. scenarios, while maintaining competitive or superior accuracy on clean data.
title Client-Side Patching against Backdoor Attacks in Federated Learning
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2412.10605