ARIBA: Towards Accurate and Robust Identification of Backdoor Attacks in Federated Learning

02/09/2022
by   Yuxi Mi, et al.
0

The distributed nature and privacy-preserving characteristics of federated learning make it prone to the threat of poisoning attacks, especially backdoor attacks, where the adversary implants backdoors to misguide the model on certain attacker-chosen sub-tasks. In this paper, we present a novel method ARIBA to accurately and robustly identify backdoor attacks in federated learning. By empirical study, we observe that backdoor attacks are discernible by the filters of CNN layers. Based on this finding, we employ unsupervised anomaly detection to evaluate the pre-processed filters and calculate an anomaly score for each client. We then identify the most suspicious clients according to their anomaly scores. Extensive experiments are conducted, which show that our method ARIBA can effectively and robustly defend against multiple state-of-the-art attacks without degrading model performance.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/20/2020

Mitigating Sybil Attacks on Differential Privacy based Federated Learning

In federated learning, machine learning and deep learning models are tra...
research
10/12/2022

Anomaly Detection via Federated Learning

Machine learning has helped advance the field of anomaly detection by in...
research
09/06/2021

Byzantine-Robust Federated Learning via Credibility Assessment on Non-IID Data

Federated learning is a novel framework that enables resource-constraine...
research
03/01/2023

Mitigating Backdoors in Federated Learning with FLD

Federated learning allows clients to collaboratively train a global mode...
research
07/02/2018

How To Backdoor Federated Learning

Federated learning enables multiple participants to jointly construct a ...
research
09/09/2022

Anomaly Detection through Unsupervised Federated Learning

Federated learning (FL) is proving to be one of the most promising parad...
research
07/28/2022

Privacy-Preserving Federated Recurrent Neural Networks

We present RHODE, a novel system that enables privacy-preserving trainin...

Please sign up or login with your details

Forgot password? Click here to reset