A sparse and invisible targeted backdoor attack in federated learning
摘要
In distributed edge Computing scenarios within the Internet of Things (IoT), individual clients are susceptible to adversarial backdoor attacks, wherein malicious modifications to local data may be introduced. Such compromised clients can negatively impact the integrity and performance of the global model during federated learning. Existing backdoor attack techniques suffer from low attack success rates and poor trigger concealment. To address this issue, this paper proposes a novel Sparse and Invisible Targeted Backdoor (SITB) attack method. The key advantages of SITB are as follows: (1) A sparse and invisible trigger generation approach is introduced, enforcing sparsity and invisibility constraints during optimization to enhance trigger concealment. (2) In sparse constraints, by ranking gradient values and selecting pixels most sensitive to the model, the method achieves a high attack success rate. Extensive experiments on the CIFAR-10 public dataset and PathMNIST dataset validate the effectiveness of the proposed method. Results show that the attack success rate on poisoned data surpasses existing methods by 5–10%. Furthermore, the quantitative assessment of visual quality, conducted both prior to and subsequent to poisoning, affirmed that the generated trigger exhibited a high degree of stealthiness, boasting a PSNR value as high as 40 and an SSIM value as high as 0.99. In addition, SPAM and SRM are extremely low. Moreover, it demonstrates robust resistance against multiple federated learning defense mechanisms.