详细信息

A sparse and invisible targeted backdoor attack in federated learning  ( SCI-EXPANDED收录)  

文献类型:期刊文献

英文题名:A sparse and invisible targeted backdoor attack in federated learning

作者:Zhang, Qikun[1];Yu, Mengyang[1];Wang, Ruifang[1];Li, Yongjiao[2];Yuan, Junling[1];Tan, Yu-an[3]

机构:[1]Zhengzhou Univ Light Ind, Sch Comp Sci & Technol, Zhengzhou 450002, Henan, Peoples R China;[2]East China Univ Sci & Technol, Dept & Org, Minist Educ, Key Lab Smart Mfg Energy Chem Proc, Shanghai, Peoples R China;[3]Beijing Inst Technol, Sch Comp Sci & Technol, Beijing, Peoples R China

年份:2025

卷号:37

期号:6

外文期刊名:JOURNAL OF KING SAUD UNIVERSITY COMPUTER AND INFORMATION SCIENCES

收录:;WOS:【SCI-EXPANDED(收录号:WOS:001536297700005)】;

基金:This work is supported by the National Natural Science Foundation of China under Grant (No. 61971380, 61772477), and the key technologies R&D Program of Henan Province (No. 252102211089, 252102211112), and the research funding of Key Laboratory of Big Data Intelligent Computing (No. BDIC2023B006).

语种:英文

外文关键词:Internet of things; Federated learning; Backdoor attack; Invisibility; Security

摘要:In distributed edge Computing scenarios within the Internet of Things (IoT), individual clients are susceptible to adversarial backdoor attacks, wherein malicious modifications to local data may be introduced. Such compromised clients can negatively impact the integrity and performance of the global model during federated learning. Existing backdoor attack techniques suffer from low attack success rates and poor trigger concealment. To address this issue, this paper proposes a novel Sparse and Invisible Targeted Backdoor (SITB) attack method. The key advantages of SITB are as follows: (1) A sparse and invisible trigger generation approach is introduced, enforcing sparsity and invisibility constraints during optimization to enhance trigger concealment. (2) In sparse constraints, by ranking gradient values and selecting pixels most sensitive to the model, the method achieves a high attack success rate. Extensive experiments on the CIFAR-10 public dataset and PathMNIST dataset validate the effectiveness of the proposed method. Results show that the attack success rate on poisoned data surpasses existing methods by 5-10%. Furthermore, the quantitative assessment of visual quality, conducted both prior to and subsequent to poisoning, affirmed that the generated trigger exhibited a high degree of stealthiness, boasting a PSNR value as high as 40 and an SSIM value as high as 0.99. In addition, SPAM and SRM are extremely low. Moreover, it demonstrates robust resistance against multiple federated learning defense mechanisms.

参考文献:

正在载入数据...

版权所有©华东理工大学 重庆维普资讯有限公司 渝B2-20050021-7 
渝公网安备 50019002500408号 违法和不良信息举报中心