BadCleaner: Defending Backdoor Attacks in Federated Learning Via Attention-Based Multi-Teacher Distillation

后门 计算机科学 人工智能 计算机安全 机器学习
作者
Jiale Zhang,Chengcheng Zhu,Chunpeng Ge,Chuan Ma,Yanchao Zhao,Xiaobing Sun,Bing Chen
出处
期刊:IEEE Transactions on Dependable and Secure Computing [IEEE Computer Society]
卷期号:21 (5): 4559-4573 被引量:6
标识
DOI:10.1109/tdsc.2024.3354049
摘要

As a privacy-preserving distributed learning paradigm, federated learning (FL) has been proven to be vulnerable to various attacks, among which backdoor attack is one of the toughest. In this attack, malicious users attempt to embed backdoor triggers into local models, resulting in the crafted inputs being misclassified as the targeted labels. To address such attack, several defense mechanisms are proposed, but may lose the effectiveness due to the following drawbacks. First, current methods heavily rely on massive labeled clean data, which is an impractical setting in FL. Moreover, an in-avoidable performance degradation usually occurs in the defensive procedure. To alleviate such concerns, we propose BadCleaner , a lossless and efficient backdoor defense scheme via attention-based federated multi-teacher distillation. Firstly, BadCleaner can effectively tune the backdoored joint model without performance degradation, by distilling the in-depth knowledge from multiple teachers with only a small part of unlabeled clean data. Secondly, to fully eliminate the hidden backdoor patterns, we present an attention transfer method to alleviate the attention of models to the trigger regions. The extensive evaluation demonstrates that BadCleaner can reduce the success rates of state-of-the-art backdoor attacks without compromising the model performance.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
虞访云完成签到,获得积分10
刚刚
拼搏的飞薇完成签到,获得积分10
1秒前
Robert完成签到,获得积分10
1秒前
格子完成签到,获得积分10
2秒前
陆陆完成签到 ,获得积分10
2秒前
2秒前
splemeth完成签到,获得积分10
2秒前
优雅含莲完成签到 ,获得积分0
2秒前
英姑应助BaiX采纳,获得10
3秒前
勤恳枕头完成签到,获得积分10
3秒前
sssss完成签到,获得积分10
4秒前
QQ完成签到,获得积分10
4秒前
温暖的木瓜完成签到 ,获得积分10
5秒前
艾泽拉斯的囚徒完成签到,获得积分10
5秒前
任性的诗兰完成签到,获得积分10
5秒前
Jun发布了新的文献求助10
5秒前
lhl完成签到,获得积分10
5秒前
MaxZimmer完成签到,获得积分10
5秒前
Fiona完成签到,获得积分10
6秒前
亮倪力完成签到,获得积分10
6秒前
大头宝宝168完成签到,获得积分10
6秒前
fuluyuzhe_668完成签到,获得积分10
6秒前
123完成签到,获得积分10
7秒前
phil完成签到,获得积分10
7秒前
南宫若翠完成签到,获得积分10
8秒前
adai完成签到,获得积分10
8秒前
多肉丸子完成签到,获得积分10
8秒前
勤恳的德地完成签到,获得积分10
9秒前
9秒前
Chen完成签到 ,获得积分10
9秒前
叮当猫完成签到,获得积分10
10秒前
lawson完成签到,获得积分10
10秒前
昊康好完成签到,获得积分10
10秒前
勤奋酒窝完成签到,获得积分10
11秒前
轻松的小白菜完成签到,获得积分10
12秒前
月牙儿完成签到 ,获得积分10
12秒前
子非鱼完成签到,获得积分10
13秒前
13秒前
哈哈哈完成签到,获得积分10
14秒前
AllRightReserved应助魔幻网络采纳,获得10
14秒前
高分求助中
Adhesion Science: Principles & Practice 1234
Signals, Systems, and Signal Processing 610
Burger's Medicinal Chemistry and Drug Discovery 400
A Step-by-Step Guide to Qualitative Data Coding 2nd Edition 400
Impact of Storage Orientation and Duration on Prefilled Syringe Performance: Break-Loose and Glide Forces, and Injection Time Across Multiple Time Points 360
Programming for Chemical Engineers Using C, C++, and MATLAB 300
Upland Kenya wild flowers and ferns: a flora of the flowers, ferns, grasses, and sedges of highland Kenya 300
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6664070
求助须知:如何正确求助?哪些是违规求助? 8413933
关于积分的说明 17985470
捐赠科研通 5869018
什么是DOI,文献DOI怎么找? 2975322
邀请新用户注册赠送积分活动 1951216
关于科研通互助平台的介绍 1877565