Data Poisoning Attacks on Federated Learning by Using Adversarial Samples

Lei Shi,Zhen Chen,Yucheng Shi,Guangtao Zhao,Lin Wei,Yongcai Tao,Yufei Gao
DOI: https://doi.org/10.1109/icceai55464.2022.00041
2022-01-01
Abstract:Federated learning has grown increasingly in academia and industry. It has the strong ability to train joint models among numerous parties without local data exchange. Since federated learning does not have access to the training process of participants, it is vulnerable to poisoning attacks by attackers, that is, attackers can compromise the accuracy of jointly trained models by uploading elaborate malicious local updates to the server in the guise of normal participants. However, traditional attacks such as label flipping attack and Gaussian noise attack are less effective in untargeted attacks against robust federation learning. To address above issues, we focus on applying adversarial samples to jeopardize the accuracy of the training model, which is rarely explored for verifying the security of federated learning. In this paper, we propose a novel poisoning attack algorithm Fed-MIFGSM against the robust federated learning framework to investigate the impact of adversarial samples on federated learning. Experiments show that federated learning is vulnerable to attacks from adversarial samples with more than 5% reduction of the accuracy under different scenarios.
What problem does this paper attempt to address?