Pith. sign in

REVIEW 1 cited by

Concealing Backdoor Model Updates in Federated Learning by Trigger-Optimized Data Poisoning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2405.06206 v2 pith:A35BVQGS submitted 2024-05-10 cs.CR cs.AIcs.LG

classification cs.CRcs.AIcs.LG
keywords backdoormodelupdatesdataattackattacksdpotlearning
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated Learning (FL) is a decentralized machine learning method that enables participants to collaboratively train a model without sharing their private data. Despite its privacy and scalability benefits, FL is susceptible to backdoor attacks, where adversaries poison the local training data of a subset of clients using a backdoor trigger, aiming to make the aggregated model produce malicious results when the same backdoor condition is met by an inference-time input. Existing backdoor attacks in FL suffer from common deficiencies: fixed trigger patterns and reliance on the assistance of model poisoning. State-of-the-art defenses based on analyzing clients' model updates exhibit a good defense performance on these attacks because of the significant divergence between malicious and benign client model updates. To effectively conceal malicious model updates among benign ones, we propose DPOT, a backdoor attack strategy in FL that dynamically constructs backdoor objectives by optimizing a backdoor trigger, making backdoor data have minimal effect on model updates. We provide theoretical justifications for DPOT's attacking principle and display experimental results showing that DPOT, via only a data-poisoning attack, effectively undermines state-of-the-art defenses and outperforms existing backdoor attack techniques on various datasets.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. DROP: Poison Dilution via Knowledge Distillation for Federated Learning

    cs.LG 2025-02 conditional novelty 6.0 of 10

    DROP combines clustering, client reputation tracking, and GAN-guided knowledge distillation to suppress targeted backdoor attacks in federated learning, reporting under 2% attack success in most tested IID settings.

Pith tools