错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Poison Egg: Scrambling Federated Learning with Delayed Backdoor Attack

  • Masayoshi Tsutsui,
  • Tatsuya Kaneko,
  • Shinya Takamaeda-Yamazaki

摘要

Federated learning (FL) is a distributed machine learning method in which edge devices collaboratively train a global model without disclosing their private training data to others. Because many clients participate in FL, the global model is constantly exposed to the risk of attacks by malicious clients. In particular, backdoor attacks, which modify the global model to misclassify inputs with specific features, pose a significant threat. Feedback-based methods are regarded as effective defenses to achieve high robustness by monitoring the accuracy of the global model and rolling back its state if there is an abnormality. Against feedback-based methods, we propose Poison Egg, which is a delayed backdoor attack that scrambles the FL training process. Poison Egg exposes the vulnerability underlying the assumptions of feedback-based defense methods that model anomalies occur immediately after an attack. Poison Egg deceives feedback-based defenses by intentionally delaying the occurrence of anomalies. Through Poison Egg, we demonstrate the necessity of novel defense mechanisms against backdoor attacks in FL.