Backdoor Attacks and Defense in FL
摘要
Federated Learning (FL) has received significant interest from both the research field and industry perspective. One of the most promising cross-silo applications on FL is electronic health. In this application, clients can be different hospitals or health centers in geo-distributed locations. A central orchestration server (superior health center) organizes the training while never seeing patients’ raw data. However, FL-based electronic health system is vulnerable to backdoor attack. The backdoored joint global model will produce an adversary-expected output when a predefined trigger is attached to its input, but it will behave normally for clean inputs. This vulnerability is exacerbated by the distributed nature of FL, making detecting backdoor attacks on FL a challenging work. In this chapter, we demonstrate that any local hospital in such a collaborative training framework can introduce hidden backdoor functionality into the joint global model. Based on the coalitional game and Shapley value, we introduce an effective and real-time backdoor detection system on FL. Extensive experiments on two machine learning tasks show that the presented detection scheme achieves high accuracy and is robust against multi-attacker settings.