Defense Strategy in Federated Learning: Unveiling Stealthy Threats and the Similarity Filter Solution
摘要
Federated Learning (FL) empowers multiple clients to collaboratively train a global model while preserving the confidentiality of their local datasets. Adversaries can secretly introduce specific triggers into benign samples and manipulate sample labels to launch a covert attack on the FL system, effectively evading detection. The compromised model operates normally with benign samples but concedes to the demands of the attackers when presented with samples bearing these concealed triggers. To broaden the scope of backdoor incursions, this paper delves into the realm of frequency domain attack in FL, showcasing their effective offensive capabilities and remarkable stealth when in a centralized context. This method of attack involves the manipulation of amplitude in the frequency domain of an image to subtly introduce a backdoor across the entire sample domain. Our observations reveal that frequency domain attack are exceedingly adept at circumventing existing defenses in FL and are nearly impervious to detection, resulting in an exceptionally high rate of attack success. Furthermore, to counteract frequency domain attack, we introduce an innovative defensive measure known as the Similarity Filter (SF). Extensive experiments validate the efficacy of SF in protecting FL from frequency domain attack, demonstrating remarkable defensive capabilities against other cutting-edge attack methodologies.