BadHAR: Backdoor Attacks in Federated Human Activity Recognition Systems
摘要
With the rapid development of Internet of Things (IoT) technology, Human Activity Recognition (HAR) has seen increasingly widespread applications in daily life, such as in health monitoring and activity tracking features commonly found in smartphones and smartwatches. However, despite the significant advancements in preserving user privacy through federated learning, numerous challenges remain, particularly in terms of security. During the training process in federated learning, the data on participating client devices is not visible to the server, making the system vulnerable to attacks by malicious clients. Specifically, a malicious client may use backdoor-infused data to train its local model, which can then compromise the global model when the server aggregates these models. To the best of our knowledge, no existing research has addressed the issue of backdoor attacks in Federated Human Activity Recognition. To address this gap, we propose an effective method for generating HAR backdoor data based on observations from public datasets. Experimental results indicate that our backdoor attack method achieves excellent attack success rates across six public HAR datasets. Our work offers new insights and potential solutions for enhancing the security of HAR models in federated learning.