STDLens: Model Hijacking-Resilient Federated Learning for Object Detection

03/21/2023
by   Ka-Ho Chow, et al.
0

Federated Learning (FL) has been gaining popularity as a collaborative learning framework to train deep learning-based object detection models over a distributed population of clients. Despite its advantages, FL is vulnerable to model hijacking. The attacker can control how the object detection system should misbehave by implanting Trojaned gradients using only a small number of compromised clients in the collaborative learning process. This paper introduces STDLens, a principled approach to safeguarding FL against such attacks. We first investigate existing mitigation mechanisms and analyze their failures caused by the inherent errors in spatial clustering analysis on gradients. Based on the insights, we introduce a three-tier forensic framework to identify and expel Trojaned gradients and reclaim the performance over the course of FL. We consider three types of adaptive attacks and demonstrate the robustness of STDLens against advanced adversaries. Extensive experiments show that STDLens can protect FL against different model hijacking attacks and outperform existing methods in identifying and removing Trojaned gradients with significantly higher precision and much lower false-positive rates.

READ FULL TEXT

page 1

page 3

page 4

page 6

page 7

page 8

research
06/30/2023

Federated Object Detection for Quality Inspection in Shared Production

Federated learning (FL) has emerged as a promising approach for training...
research
11/04/2020

BaFFLe: Backdoor detection via Feedback-based Federated Learning

Recent studies have shown that federated learning (FL) is vulnerable to ...
research
10/28/2021

Gradient Inversion with Generative Image Prior

Federated Learning (FL) is a distributed learning framework, in which th...
research
12/04/2022

Security Analysis of SplitFed Learning

Split Learning (SL) and Federated Learning (FL) are two prominent distri...
research
06/30/2023

Federated Ensemble YOLOv5 - A Better Generalized Object Detection Algorithm

Federated learning (FL) has gained significant traction as a privacy-pre...
research
11/29/2021

Anomaly Localization in Model Gradients Under Backdoor Attacks Against Federated Learning

Inserting a backdoor into the joint model in federated learning (FL) is ...
research
01/28/2021

Covert Model Poisoning Against Federated Learning: Algorithm Design and Optimization

Federated learning (FL), as a type of distributed machine learning frame...

Please sign up or login with your details

Forgot password? Click here to reset