USENIX Security2022Top-tier venue
FLAME: Taming Backdoors in Federated Learning
Thien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame, Helen Möllering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, Azalia Mirhoseini, Shaza Zeitouni, Farinaz Koushanfar, Ahmad-Reza Sadeghi, Thomas Schneider
Abstract
Federated Learning (FL) is a collaborative machine learning approach allowing participants to jointly train a model without sharing their private, potentially sensitive local datasets with others. Despite its benefits, FL is vulnerable to so-called backdoor attacks, in which an adversary injects manipulated model updates into the federated model aggregation process so that the resulting model will provide targeted false predictions for specific adversary-chosen inputs. Proposed defenses against backdoor attacks based on detecting and filtering out malicious model updates consider only very specific and limited attacker models, whereas defenses based on differential privacy-inspired noise injection significantly deteriorate the benign performance of the aggregated model. To address these deficiencies, we introduce FLAME, a defense framework that estimates the sufficient amount of noise to be injected to ensure the elimination of backdoors. To minimize the required amount of noise, FLAME uses a model clustering and weight clipping approach. This ensures that FLAME can maintain the benign performance of the aggregated model while effectively eliminating adversarial backdoors. Our evaluation of FLAME on several datasets stemming from application areas, including image classification, word prediction, and IoT intrusion detection, demonstrates that FLAME removes backdoors effectively with a negligible impact on the benign performance of the models. Furthermore, following the considerable attention that our research has received after its presentation at USENIX SEC 2022, FLAME has become the subject of numerous investigations proposing diverse attack methodologies in an attempt to circumvent it. As a response to these endeavors, we provide a comprehensive analysis of these attempts. Our findings show that these papers (e.g., 3DFed [36]) have not fully comprehended nor correctly employed the fundamental principles underlying FLAME. Moreover, their evaluations appear to be incomplete, with handpicked results chosen selectively. Consequently, in succinct terms, our defense mechanism, FLAME, effectively repels these attempted attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 08ebcae5-fd58-4e94-be26-5cb6f001e6beCited by top-tier papers75
- A3FL: Adversarially Adaptive Backdoor Attacks to Federated LearningHangfan Zhang, Jinyuan Jia, Jinghui Chen, Lu Lin et al.NeurIPS 2023 · 102 citations
- IBA: Towards Irreversible Backdoor Attacks in Federated LearningThuy Dung Nguyen, Tuan Nguyen, Anh Tran, Khoa D. Doan et al.NeurIPS 2023 · 94 citations
- Multi-metrics adaptively identifies backdoors in Federated learningSiquan Huang, Yijiang Li, Chong Chen, Leyu Shi et al.ICCV 2023 · 56 citations
- Privacy Side Channels in Machine Learning SystemsEdoardo Debenedetti, Giorgio Severi, Milad Nasr, Christopher A. Choquette-Choo et al.USENIX Security 2024 · 52 citations
- Chameleon: Adapting to Peer Images for Planting Durable Backdoors in Federated LearningYanbo Dai, Songze LiICML 2023 · 45 citations
Builds on17
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
Related papers
- Defending against Backdoors in Federated Learning with Robust Learning RateMustafa Safa Özdayi, Murat Kantarcioglu, Yulia R. GelAAAI 2021 · 250 citations
- BayBFed: Bayesian Backdoor Defense for Federated LearningKavita Kumari, Phillip Rieger, Hossein Fereidooni, Murtuza Jadliwala et al.S&P 2023
- On the Vulnerability of Backdoor Defenses for Federated LearningPei Fang, Jinghui ChenAAAI 2023 · 66 citations
- DeepSight: Mitigating Backdoor Attacks in Federated Learning Through Deep Model InspectionPhillip Rieger, Thien Duc Nguyen, Markus Miettinen, Ahmad-Reza SadeghiNDSS 2022
- CrowdGuard: Federated Backdoor Detection in Federated LearningPhillip Rieger, Torsten Krauß, Markus Miettinen, Alexandra Dmitrienko et al.NDSS 2024
