SemSBA: Semantic-perturbed Stealthy Backdoor Attack on Federated Semi-supervised Learning

Yingrui Tong,Jun Feng,Gaolei Li,Xi Lin,Chengcheng Zhao,Xiaoyu Yi,Jianhua Li
DOI: https://doi.org/10.1109/icpads60453.2023.00221
2023-01-01
Abstract:Federated semi-supervised learning (FSSL) has been perceived as a promising approach that leverages semi-supervised learning and federated learning (FL) to provide powerful privacy preservation while reducing the burden on human supervision. However, due to the lack of strict participant identification and the significant proportion of unlabeled samples, FSSL is more susceptible to covert backdoor attacks than traditional machine learning. To validate this speculation, a novel semantic-perturbed stealthy backdoor attack (SemSBA) scheme is proposed for FSSL-based systems. In SemSBA, we select original natural semantic features in the unlabeled training samples as backdoor triggers and then generate poisoned samples by adding adversarial perturbations that move them across the model decision boundary. With SemSBA, the adversary can trigger the hidden backdoor in the victim model during the inference stage without any deliberate modifications on testing samples. To further improve the strength and robustness of the attack, a pseudo label steering enhancement strategy is also designed to perturb the weakly-augmented version of unlabeled samples to induce target pseudo label allocations. Additionally, to improve the attack success rate, we amplify the weight of the local backdoored model during FSSL’s model aggregation process to manipulate the game between benign clients and malicious clients. Extensive experiments based on two benchmark datasets demonstrate that the proposed SemSBA scheme can achieve comparable stealthiness against existing attacks.
What problem does this paper attempt to address?