DSBP: Data-free and Swift Backdoor Purification for Trustworthy Federated Learning via Multi-teacher Adversarial Distillation

Gaolei Li,Yuanyuan Zhao,Jun Wu,Jianhua Li,Longfei Zheng
Abstract:Federated learning (FL) faces with severe backdoor 1 threats. Due to the inaccessibility of clean sam-2 ples, the parameter server cannot clean them up in 3 real time even if poisoning features are discovered. 4 Meanwhile, existing backdoor defence methods al-5 ways require sacrificing model accuracy or increas-6 ing communication delay in exchange for better FL 7 trustworthiness, which is unpractical in real sce-8 narios. To address these challenges, we propose 9 a novel data-free and swift backdoor purification 10 (DSBP) scheme based on multi-teacher adversar-11 ial distillation, which can effectively erase various 12 backdoor variants in FL. The DSBP treats the pu-13 rification task as an adversarial game process be-14 tween knowledge inheritance and backdoor inhibi-15 tion, with the goal of enforcing the student model 16 to learn the ensemble results of multiple teacher 17 models on reconstructed clean samples, while be-18 ing insensitive to synthetic poisoned samples. In 19 DSBP, we propose to utilize the self-similarity of 20 poisoned features to optimize the trigger gener-21 ator, which is essential to accelerate the conver-22 gence of DSBP during the adversarial distillation 23 process. We validate that the effectiveness of pro-24 posed DBSP by comparing with 4 state of-the-art 25 defense approaches against 3 backdoor variants on 26 3 datasets. The aversage attack success rate can be 27 reduced from 96.6% to 2.3% with only 200 epochs. 28
Computer Science
What problem does this paper attempt to address?