LR-BA: Backdoor attack against vertical federated learning using local latent representations. Issue 129 (June 2023)
- Record Type:
- Journal Article
- Title:
- LR-BA: Backdoor attack against vertical federated learning using local latent representations. Issue 129 (June 2023)
- Main Title:
- LR-BA: Backdoor attack against vertical federated learning using local latent representations
- Authors:
- Gu, Yuhao
Bai, Yuebin - Abstract:
- Abstract: In vertical federated learning (VFL), multiple participants can collaborate in training a model with distributed data features and labels managed by one of them. The cooperation provides opportunities for a malicious participant to conduct a backdoor attack. However, the attack is challenging when the adversary does not own labels with the mitigation of other participants. In this paper, we discover that an adversary can exploit local latent representations output in the inference stage to inject a backdoor in VFL, even without access to labels. With little auxiliary labeled data, the adversary fine-tunes its bottom model to make it output specific latent representation for backdoor input instances, which induces the federated model to predict the attacker-specified label regardless of benign participants. Our experiments show that the proposed attack can achieve a high attack success rate with little loss of main task accuracy and outperform existing backdoor attacks. We also explore possible defenses against the attack. Our research demonstrates the potential security threat to VFL.
- Is Part Of:
- Computers & security. Issue 129(2023)
- Journal:
- Computers & security
- Issue:
- Issue 129(2023)
- Issue Display:
- Volume 129, Issue 129 (2023)
- Year:
- 2023
- Volume:
- 129
- Issue:
- 129
- Issue Sort Value:
- 2023-0129-0129-0000
- Page Start:
- Page End:
- Publication Date:
- 2023-06
- Subjects:
- Vertical federated learning -- Backdoor attack -- Backdoor defense -- Federated learning security -- Artificial intelligence security
FL Federated Learning -- HFL Horizontal Federated Learning -- VFL Vertical Federated Learning -- SHAP SHapley Additive exPlanations -- MSE Mean Square Error -- CE Cross Entropy -- BHI Breast Histopathology Images -- FCN Fully Connected Network -- BERT Bidirectional Encoder Representations from Transformers -- SGD Stochastic Gradient Descent -- ASR Attack Success Rate -- PCA Principal Component Analysis
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2023.103193 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 27035.xml