Robust Federated Learning for Ubiquitous Computing through Mitigation of Edge-Case Backdoor Attacks
"Federated Learning (FL) allows several data owners to train a joint model without sharing their training data. Such a paradigm is useful for better privacy in many ubiquitous computing systems. However, FL is vulnerable to poisoning attacks, where malicious participants attempt to inject a backdoor task in the model at training time, along with the main task that the model was initially trained for. Recent works show that FL is particularly vulnerable to edge-case backdoors introduced by data points with unusual out-of-distribution features. Such attacks are among the most difficult to counter, and today's FL defense mechanisms usually fail to tackle them. In this paper, we present ARMOR, a defense mechanism that leverages adversarial learning to uncover edge-case backdoors. In contrast to most of existing FL defenses, ARMOR does not require real data samples and is compatible with secure aggregation, thus, providing better FL privacy protection. ARMOR relies on GANs (Generative Adversarial Networks) to extract data features from model updates, and uses the generated samples to test the activation of potential edge-case backdoors in the model. Our experimental evaluations with three widely used datasets and neural networks show that ARMOR can tackle edge-case backdoors with 95% resilience against attacks, and without hurting model quality. https://doi.org/10.1145/3569492"
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can edge-case backdoor attacks in federated learning (where attackers inject tasks via anomalous data points) be detected and mitigated?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- How does the ARMOR framework detect edge-case backdoor attacks without access to real data?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- Can ARMOR improve the security and robustness of federated learning without compromising privacy protection?Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
Practical Problems
1- Federated learning systems are vulnerable to privacy leakage and edge-case backdoor attacks.Category: Privacy-Enhancing TechnologiesSimilar questionsarrow_forward
- 80%
UMLAUT: Debugging Deep Learning Programs using Program Structure and Model Behavior
CHI '21· Explainable AI (XAI) +1
- 80%
Supporting Co-Adaptive Machine Teaching through Human Concept Learning and Cognitive Theories
CHI '25· Explainable AI (XAI) +1
- 67%
Questioning the AI: Informing Design Practices for Explainable AI User Experiences
CHI '20· Explainable AI (XAI) +1
- 67%
AI-Moderated Decision-Making: Capturing and Balancing Anchoring Bias in Sequential Decision Tasks
CHI '22· Explainable AI (XAI) +2
- 67%
How can Explainability Methods be Used to Support Bug Identification in Computer Vision Models?
CHI '22· Explainable AI (XAI) +1
- 67%
Watch Out For Updates: Understanding the Effects of Model Explanation Updates in AI-Assisted Decision Making
CHI '23· Explainable AI (XAI) +1
- 67%
Angler: Helping Machine Translation Practitioners Prioritize Model Improvements
CHI '23· Explainable AI (XAI) +2
- 67%
Zeno: An Interactive Framework for Behavioral Evaluation of Machine Learning
CHI '23· Explainable AI (XAI) +1
- 67%
"Are You Really Sure?'' Understanding the Effects of Human Self-Confidence Calibration in AI-Assisted Decision Making
CHI '24· Explainable AI (XAI) +1
- 67%
"AI enhances our performance, I have no doubt this one will do the same": The Placebo effect is robust to negative descriptions of AI
CHI '24· Explainable AI (XAI) +2
Based on Jaccard similarity of research subtopics & professions (≥60%)