Backdoor Attack is A Devil in Federated GAN-based Medical Image Synthesis

07/02/2022
by   Ruinan Jin, et al.
5

Deep Learning-based image synthesis techniques have been applied in healthcare research for generating medical images to support open research. Training generative adversarial neural networks (GAN) usually requires large amounts of training data. Federated learning (FL) provides a way of training a central model using distributed data from different medical institutions while keeping raw data locally. However, FL is vulnerable to backdoor attack, an adversarial by poisoning training data, given the central server cannot access the original data directly. Most backdoor attack strategies focus on classification models and centralized domains. In this study, we propose a way of attacking federated GAN (FedGAN) by treating the discriminator with a commonly used data poisoning strategy in backdoor attack classification models. We demonstrate that adding a small trigger with size less than 0.5 percent of the original image size can corrupt the FL-GAN model. Based on the proposed attack, we provide two effective defense strategies: global malicious detection and local training regularization. We show that combining the two defense strategies yields a robust medical image generation.

READ FULL TEXT

page 7

page 12

page 13

research
10/19/2022

Backdoor Attack and Defense in Federated Generative Adversarial Network-based Medical Image Synthesis

Deep Learning-based image synthesis techniques have been applied in heal...
research
07/16/2020

Data Poisoning Attacks Against Federated Learning Systems

Federated learning (FL) is an emerging paradigm for distributed training...
research
05/02/2021

GRNN: Generative Regression Neural Network – A Data Leakage Attack for Federated Learning

Data privacy has become an increasingly important issue in machine learn...
research
09/06/2021

Generation of Synthetic Electronic Health Records Using a Federated GAN

Sensitive medical data is often subject to strict usage constraints. In ...
research
01/18/2021

Reducing bias and increasing utility by federated generative modeling of medical images using a centralized adversary

We introduce FELICIA (FEderated LearnIng with a CentralIzed Adversary) a...
research
12/19/2021

FedNI: Federated Graph Learning with Network Inpainting for Population-Based Disease Prediction

Graph Convolutional Neural Networks (GCNs) are widely used for graph ana...
research
01/22/2022

FedMed-GAN: Federated Multi-Modal Unsupervised Brain Image Synthesis

Utilizing the paired multi-modal neuroimaging data has been proved to be...

Please sign up or login with your details

Forgot password? Click here to reset