paper-with-me

Papers

How Potent are Evasion Attacks for Poisoning Federated Learning-Based Signal Classifiers?

2023-01-21 · Su Wang, Rajeev Sahay, Christopher G. Brinton

There has been recent interest in leveraging federated learning (FL) for radio signal classification tasks. In FL, model parameters are periodically communicated from participating devices, training on their own local datasets, to a central server which aggregates them into a global model. While FL has privacy/security advantages due to raw data not leaving the devices, it is still susceptible to several adversarial attacks. In this work, we reveal the susceptibility of FL-based signal classifiers to model poisoning attacks, which compromise the training process despite not observing data transmissions. In this capacity, we develop an attack framework in which compromised FL devices perturb their local datasets using adversarial evasion attacks. As a result, the training process of the global model significantly degrades on in-distribution signals (i.e., signals received over channels with identical distributions at each edge device). We compare our work to previously proposed FL attacks and reveal that as few as one adversarial device operating with a low-powered perturbation under our attack framework can induce the potent model poisoning attack to the global classifier. Moreover, we find that more devices partaking in adversarial poisoning will proportionally degrade the classification performance.

📄 PDF Abstract BibTeX arXiv:2301.08866

Code (0)

등록된 구현이 없습니다.

Tasks

Federated LearningModel Poisoning

Similar Papers 제목 키워드 기반

Adversarial Robustness Unhardening via Backdoor Attacks in Federated Learning

2023-10-17 · Taejin Kim, Jiarui Li, Shubhranshu Singh, Nikhil Madaan 외

In today's data-driven landscape, the delicate equilibrium between safeguarding user privacy and unleashing data potential stands as a paramount concern. Federated learning, which enables collaborative model training wit…

Adversarial RobustnessFederated Learning

Mitigating Evasion Attacks in Federated Learning-Based Signal Classifiers

2023-06-08 · Su Wang, Rajeev Sahay, Adam Piaseczny, Christopher G. Brinton

Recent interest in leveraging federated learning (FL) for radio signal classification (SC) tasks has shown promise but FL-based SC remains susceptible to model poisoning adversarial attacks. These adversarial attacks mis…

Adversarial AttackFederated LearningModel Poisoning

Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning Attacks

2018-09-08 · Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski 외

Transferability captures the ability of an attack against a machine-learning model to be effective against a different, potentially unknown, model. Empirical evidence for transferability has been shown in previous work, …

Revamping Federated Learning Security from a Defender's Perspective: A Unified Defense with Homomorphic Encrypted Data Space

2024-01-01 · CVPR 2024 1 · K Naveen Kumar, Reshmi Mitra, C Krishna Mohan

Federated Learning (FL) facilitates clients to collaborate on training a shared machine learning model without exposing individual private data. Nonetheless FL remains susceptible to utility and privacy attacks notab…

Data PoisoningFederated Learning

Band Together: Untargeted Adversarial Training with Multimodal Coordination against Evasion-based Promotion Attacks

2026-05-07 · Guanmeng Xian, Ning Yang, Philip S. Yu arxiv

Multimodal recommender systems exploit visual and textual signals to alleviate data sparsity, but this also makes them more vulnerable to evasion-based promotion attacks. Existing defenses are largely limited to single-m…