Detecting Data Poisoning in Split Learning Using Intraclass- Distance Inflated Loss
计算机科学
数据丢失
人工智能
计算机网络
作者
Mohammad Kohankhaki,Ahmad Ayad,Mahdi Barhoush,Anke Schmeink
标识
DOI:10.1109/gcwkshps58843.2023.10464883
摘要
Data poisoning attacks are a growing threat to the security of privacy-preserving machine learning. We investigate the impact of a static label flipping attack, an instance of data poisoning attacks, on Split Learning (SL). To counteract this threat, we introduce a novel detection method. Our approach leverages an autoencoder in the split layer of the system and combines client loss scores and the distance of data points from the same class in the latent space of the autoencoder. In doing so, we gain insight into client behavior and data quality, allowing a comprehensive defense strategy. Through experiments, we validate the effectiveness of our detection mechanism to accurately identify malicious clients. By integrating our detection mechanism during training, we successfully restore the system's baseline Area Under the Receiver Operating Characteristic curve (AUROC) performance while under attack with a negligible decrease (down to 0.001 in AUROC) by excluding malicious clients from the collaborative training. Our research underscores the importance of tackling data poisoning attacks within SL systems, thereby enhancing their overall security and robustness.