FLAME: Taming Backdoors in Federated Learning
Thien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame, Helen Möllering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, Azalia Mirhoseini, Shaza Zeitouni, Farinaz Koushanfar, Ahmad-Reza Sadeghi, Thomas Schneider
摘要
Federated Learning (FL) is a collaborative machine learning approach allowing participants to jointly train a model without sharing their private, potentially sensitive local datasets with others. Despite its benefits, FL is vulnerable to so-called backdoor attacks, in which an adversary injects manipulated model updates into the federated model aggregation process so that the resulting model will provide targeted false predictions for specific adversary-chosen inputs. Proposed defenses against backdoor attacks based on detecting and filtering out malicious model updates consider only very specific and limited attacker models, whereas defenses based on differential privacy-inspired noise injection significantly deteriorate the benign performance of the aggregated model. To address these deficiencies, we introduce FLAME, a defense framework that estimates the sufficient amount of noise to be injected to ensure the elimination of backdoors. To minimize the required amount of noise, FLAME uses a model clustering and weight clipping approach. This ensures that FLAME can maintain the benign performance of the aggregated model while effectively eliminating adversarial backdoors. Our evaluation of FLAME on several datasets stemming from application areas, including image classification, word prediction, and IoT intrusion detection, demonstrates that FLAME removes backdoors effectively with a negligible impact on the benign performance of the models. Furthermore, following the considerable attention that our research has received after its presentation at USENIX SEC 2022, FLAME has become the subject of numerous investigations proposing diverse attack methodologies in an attempt to circumvent it. As a response to these endeavors, we provide a comprehensive analysis of these attempts. Our findings show that these papers (e.g., 3DFed [36]) have not fully comprehended nor correctly employed the fundamental principles underlying FLAME. Moreover, their evaluations appear to be incomplete, with handpicked results chosen selectively. Consequently, in succinct terms, our defense mechanism, FLAME, effectively repels these attempted attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper75
- A3FL: Adversarially Adaptive Backdoor Attacks to Federated LearningHangfan Zhang, Jinyuan Jia, Jinghui Chen, Lu Lin 等NeurIPS 2023 · 被引用 102 次
- IBA: Towards Irreversible Backdoor Attacks in Federated LearningThuy Dung Nguyen, Tuan Nguyen, Anh Tran, Khoa D. Doan 等NeurIPS 2023 · 被引用 94 次
- Multi-metrics adaptively identifies backdoors in Federated learningSiquan Huang, Yijiang Li, Chong Chen, Leyu Shi 等ICCV 2023 · 被引用 56 次
- Privacy Side Channels in Machine Learning SystemsEdoardo Debenedetti, Giorgio Severi, Milad Nasr, Christopher A. Choquette-Choo 等USENIX Security 2024 · 被引用 52 次
- Chameleon: Adapting to Peer Images for Planting Durable Backdoors in Federated LearningYanbo Dai, Songze LiICML 2023 · 被引用 45 次
它引用的顶会 Paper17
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard 等USENIX Security 2017 · 被引用 2,003 次
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 被引用 1,778 次
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 被引用 1,736 次
相关 Paper
- Defending against Backdoors in Federated Learning with Robust Learning RateMustafa Safa Özdayi, Murat Kantarcioglu, Yulia R. GelAAAI 2021 · 被引用 250 次
- BayBFed: Bayesian Backdoor Defense for Federated LearningKavita Kumari, Phillip Rieger, Hossein Fereidooni, Murtuza Jadliwala 等S&P 2023
- On the Vulnerability of Backdoor Defenses for Federated LearningPei Fang, Jinghui ChenAAAI 2023 · 被引用 66 次
- DeepSight: Mitigating Backdoor Attacks in Federated Learning Through Deep Model InspectionPhillip Rieger, Thien Duc Nguyen, Markus Miettinen, Ahmad-Reza SadeghiNDSS 2022
- CrowdGuard: Federated Backdoor Detection in Federated LearningPhillip Rieger, Torsten Krauß, Markus Miettinen, Alexandra Dmitrienko 等NDSS 2024
