FIBA: Federated Invisible Backdoor Attack
Abstract
Although previous studies have proposed backdoor attacks in Federated Learning (FL), the introduced triggers in these works are easily detectable by human eyes. Besides, this paper also shows that traditional invisible centralized backdoor attacks struggle to work well in FL scenarios. To address this issue, we propose the Federated Invisible Backdoor Attack (FIBA), a novel approach to invisible backdoor attacks against FL. FIBA can balance effectiveness and stealthiness through the auto-adjusted Quality-of-Experience (QoE) restriction and attention-based L2 regularization. It further enhances durability by targeting stable neural connections. Experimental results indicate FIBA’s superior effectiveness, comparable stealthiness, and increased durability over existing methods, demonstrating its ability to bypass current detection mechanisms and robust aggregation techniques in FL. Our codes are available here <sup xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">1</sup> .
BibTeX
@inproceedings{icassp2024_fibafederatedinv,
title = {FIBA: Federated Invisible Backdoor Attack},
author = {Lu Zhang and Baolin Zheng},
booktitle = {ICASSP 2024},
year = {2024}
}