基于离散余弦变换的联邦学习后门攻击OA
Backdoor Attack on Federated Learning Based on Discrete Cosine Transform
联邦学习是一种分布式机器学习方法,允许不同参与者利用各自的本地数据集共同训练机器学习模型,以解决数据孤岛和用户隐私保护问题.但是由于联邦学习的分布式特性易受后门攻击的影响,由此提出基于离散余弦变换的后门生成方案(FLDCTBA).该方案通过离散余弦变换获取原始图片与触发器图片的幅度谱和相位谱,将图片幅度谱进行线性组合,然后与原图片相位谱结合,通过逆离散余弦变换恢复图像.在 MNIST 数据集、Fashion-MNIST数据集和 CIFAR10 数据集上进行训练,并按照独立同分布与非独立同分布两种方式进行数据集划分.实验结果表明,与像素后门攻击和标签翻转攻击进行对比,后门生成方案能够在维持主任务准确率的同时,具有较高的攻击成功率.
Federated learning(FL)is a distributed machine learning approach that allow different partic-ipants to collaboratively train a machine learning model using their respective local datasets.The issues of data silos and user privacy protection can be addressed.However,due to the distributed nature of FL,it was susceptible to backdoor attacks.A backdoor generation scheme,FLDCTBA,utilizing discrete cosine transform(DCT)was proposed.DCT was utilized by this approach to obtain the amplitude and phase spectra of both the original and trigger images.The amplitude spectra of the images were linearly com-bined and then integrated with the phase spectrum of the original image to reconstruct the image via in-verse DCT.Training was conducted on MNIST,Fashion-MNIST,and CIFAR10 datasets,with the data-sets being divided in both independent and identically distributed(IID)and non-independent and identi-cally distributed(non-IID)manners.Compared with pixel backdoor attacks and label flipping attacks,experimental results demonstrated that FLDCTBA could achieve a high attack success rate while maintai-ning the main task accuracy.
屈昌盛;陈学斌;任志强;张镇博;李雨欣
华北理工大学 理学院 河北 唐山 063210||河北省数据科学与应用重点实验室 河北 唐山 063210||唐山市数据科学重点实验室 河北 唐山 063210华北理工大学 理学院 河北 唐山 063210||河北省数据科学与应用重点实验室 河北 唐山 063210||唐山市数据科学重点实验室 河北 唐山 063210华北理工大学 理学院 河北 唐山 063210||河北省数据科学与应用重点实验室 河北 唐山 063210||唐山市数据科学重点实验室 河北 唐山 063210华北理工大学 理学院 河北 唐山 063210||河北省数据科学与应用重点实验室 河北 唐山 063210||唐山市数据科学重点实验室 河北 唐山 063210华北理工大学 理学院 河北 唐山 063210||河北省数据科学与应用重点实验室 河北 唐山 063210||唐山市数据科学重点实验室 河北 唐山 063210
信息技术与安全科学
联邦学习后门攻击离散余弦变换隐私保护机器学习
federated learningbackdoor attackdiscrete cosine transformprivacy protectionmachine learning
《郑州大学学报(理学版)》 2026 (4)
19-26,8
国家自然科学基金项目(U20A20179)
评论