An image classification method based on federated learning in backdoor attack scenarios
Through Enhanced-Neurotoxin technology, dynamic trigger optimization and model distance control are utilized to solve the concealment and persistence problems of backdoor attacks in federated learning image classification, achieving stronger backdoor attack capabilities and better adaptability.
Patent Information
- Application Number
- CN202510020036.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-07
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-01-07
AI Technical Summary
Backdoor attacks in federated learning image classification gradually lose their effectiveness after the attack stops, and are difficult to conceal in the face of an increasing number of federated backdoor detection technologies, resulting in attack failure.
Adopting Enhanced-Neurotoxin technology, it provides enhanced backdoor attack capabilities through dynamic trigger optimization strategy and control of the distance between backdoor models and clean models, adapts to different frameworks and defense mechanisms, and reduces model differences to improve stealth and persistence.
It enhances the flexibility and stealth of backdoor attacks, can adapt to different data sets and defense mechanisms, avoids server aggregation defense, and improves the persistence and feasibility of backdoor attacks.
Smart Images

Figure CN119851035B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of federated learning image classification, and specifically provides an image classification method in a backdoor attack scenario based on federated learning. Background Art
[0002] With the continuous development of the information society, vast amounts of data have accumulated across all industries. However, due to technical, security, and regulatory constraints, private data cannot be effectively shared and aggregated, resulting in isolated data silos that severely hamper the development of machine learning. Consequently, federated learning technology has emerged. As an emerging distributed machine learning paradigm, federated learning eliminates the need for centralized data. Instead, each participant trains a model locally using private data and collaboratively learns to improve the performance of the global model. As an excellent model training method, federated learning has been widely used in image classification tasks. For example, in the medical field, medical image classification models trained using federated learning can accurately identify key information such as tumors and lesions, providing doctors with important diagnostic support.
[0003] As attack methods advance, federated learning's nature of model training and local model updates has made it vulnerable to backdoor attacks. In image classification tasks, backdoor attackers manipulate the training processes of multiple local image classification models to achieve their attack effectiveness. When encountering specific triggers, this can lead to incorrect predictions while maintaining the accuracy of normal samples. These attacks exploit the aggregated nature of federated learning, compromising model integrity across different local models without being easily detected. However, federated backdoor attacks gradually lose their effectiveness as the number of rounds increases after the attack stops, and common federated backdoor attacks cannot penetrate advanced defenses. This can lead to the failure of backdoor attacks inserted into central servers, leading to the attack's failure.
[0004] In summary, in the field of federated learning image classification, once the backdoor attack stops, the federated backdoor will gradually lose its effectiveness; with the emergence of more and more federated backdoor detection technologies, federated backdoors are not easy to insert into central servers, and the concealment of image backdoor attacks is also facing challenges. Summary of the Invention
[0005] In order to address the shortcomings of the above-mentioned existing technologies, the present invention proposes an image classification method under a backdoor attack scenario based on federated learning, in order to improve the concealment and persistence of the backdoor of federated learning image classification.
[0006] In order to achieve the above-mentioned object, the present invention adopts the following technical solutions:
[0007] The image classification method in the backdoor attack scenario based on federated learning is characterized in that it is applied to a central server, Normal clients and In a network environment composed of backdoor clients, the central server stores a test image dataset with labels. ,in, For the test images, , C is the total number of test images, Normal clients and Each backdoor client stores a local image dataset with labels, K is Normal clients and The total number of local images of each backdoor client; The local labeled private image dataset of a normal client is denoted as ,in, For the The first of the normal clients local images, for 's label; The local labeled private image dataset of the backdoor client is denoted as ,in, For the The backdoor client stores local images, for Category label; the image backdoor attack method includes the following steps:
[0008] Step 1. Define the current round as ,initialization ,definition For the serial number of any normal client, define is the serial number of any backdoor client, , ;
[0009] Definition A normal client The gradient of the local image classification model is , No. Backdoor client The gradient of the local image classification model is ;
[0010] Assume that from The backdoor attack starts in round 1, defining the central server in the first The gradient of the image classification model under the backdoor attack is , define The trigger of the wheel is ;
[0011] Step 2. The central server will Distribute to Normal clients and A backdoor client is initialized , ;
[0012] Step 3. Backdoor client exploit For local labeled private image data After processing, enter Backdoor Client The first round of local image classification model Rounds of gradient-free descent training to optimize , thus obtaining the Wheel trigger ;
[0013] Step 4. Backdoor client exploit right After processing, enter Backdoor client The first round of local image classification model Round of gradient descent training, get the Wheel gradient ;
[0014] Step 5. A normal client uses the local dataset The local image classification model Round of gradient descent training, get the Wheel gradient ;
[0015] Step 6. The central server uses formula (6) to calculate the M normal clients in the first The gradient of the round and M backdoor clients in the first The gradients of the first round are aggregated to obtain Backdoor attack on the gradient of image classification model ;
[0016] (6)
[0017] In formula (6), Represents an aggregate function;
[0018] Step 7. Assign to After that, return to step 2 and execute sequentially until the maximum number of rounds is reached, thereby obtaining the image classification model under the backdoor attack corresponding to the optimal gradient;
[0019] Step 8. The central server uses the image classification model under the backdoor attack corresponding to the optimal gradient to predict C test images and obtain C predicted category labels under the backdoor attack.
[0020] The image classification method in a backdoor attack scenario based on federated learning according to the present invention is also characterized in that step 3 includes:
[0021] Step 3.1. Using Wheel trigger For the kth image sample Perform preprocessing to obtain the kth image sample after preprocessing , After preprocessing, local images, and ; express Category label of
[0022] Step 3.2. A backdoor client will Enter Backdoor client The first round of local image classification model is processed, and the formula (1) is used to obtain Wheel trigger ;
[0023] (1)
[0024] In formula (1), ψ is a hyperparameter, for norm; is the optimization function.
[0025] Furthermore, the step 4 includes:
[0026] Step 4.1. Use formula (2) to After processing, the first images , thus obtaining a local labeled and preprocessed private image dataset ;
[0027] (2)
[0028] Step 4.2. Define the total number of rounds of local training as , the current round of local training is ,initialization , initialize the Backdoor client The local image classification model is Gradients of local training rounds ;
[0029] definition For the The backdoor client is in The distance objective function of the local training round is initialized =0;
[0030] The first Wheel Gradient After the multidimensional vector of the corresponding image classification model is expanded in one dimension, the absolute values of the vector parameters are obtained and then sorted in ascending order. The first several vector parameters are selected and their corresponding positions in the image classification model are recorded as 1, and the remaining positions are marked as 0, thereby obtaining the gradient mask of the image classification model. ;
[0031] Step 4.3. The backdoor client uses formula (3) to The local image classification model performs the e-th round of local training and obtains the Backdoor client The local image classification model is Gradients of local training rounds :
[0032] (3)
[0033] In formula (3), For the Backdoor client Gradients of the local image classification model exist On the first The gradient descent function during round training, For the Backdoor client Gradients of the local image classification model In local dataset On the first The gradient descent function during round training, ρ represents the hyperparameter;
[0034] Step 4.4. Calculate the first Backdoor client The local image classification model is +1 round of local training on the target distance function ;
[0035] (4)
[0036] In formula (4), For the Backdoor client Gradients of the local image classification model In local dataset On the first The gradient descent function during round training, is the cosine similarity function, For the Backdoor client Gradients of the local image classification model In local dataset On the first The gradient descent function during round training, for norm, , , There are 3 hyperparameters respectively;
[0037] Step 4.5. Assign to Then, return to step 4.3. and execute the steps in sequence until e> So far, the obtained Backdoor client The local image classification model is Gradients of local training rounds Assign to Backdoor client +1 round of gradients for the local image classification model .
[0038] Furthermore, the step 5 includes:
[0039] Step 5.1. Initialization , initialize the A normal client The local image classification model is Gradients of local training rounds ;
[0040] Step 5.2. A normal client sends the kth image sample Enter A normal client The first round of local image classification model is processed, and the formula (5) is used to classify the The local image classification model is used for the first Round of gradient descent training, get the A normal client The local image classification model is Gradients of local training rounds ;
[0041] (5)
[0042] Step 5.3. Assign to After that, return to step 5.2 and execute sequentially until the maximum round E is reached, so that the gradient of the local E local training is obtained. Assign to A normal client Gradients of the local image classification model .
[0043] The electronic device of the present invention includes a memory and a processor, and is characterized in that the memory is used to store a program that supports the processor to execute the image classification method in the backdoor attack scenario, and the processor is configured to execute the program stored in the memory.
[0044] The present invention provides a computer-readable storage medium, wherein a computer program is stored on the computer-readable storage medium, and the computer program is characterized in that when the computer program is executed by a processor, the steps of the image classification method in the backdoor attack scenario are executed.
[0045] Compared with the prior art, the present invention can achieve the following beneficial effects:
[0046] 1. This paper proposes an image classification method for enhanced backdoor attacks, namely Enhanced-Neurotoxin technology. This technology provides a dynamic trigger optimization strategy to enhance attack efficiency with dynamic triggers. It provides better flexibility and more powerful backdoor attack capabilities than conventional static triggers. It can adapt to the flexibility required by different frameworks, defense mechanisms and data sets, thereby optimizing attack effects.
[0047] 2. The present invention provides a strategy to control the significant difference between the backdoor model and the clean client model. By quantitatively calculating the distance between the backdoor model and the clean model, the difference between the local neural network model of the backdoor client and the normal client is reduced, successfully circumventing the server aggregation defense, and significantly improving the concealment and persistence of the backdoor.
[0048] 3. This invention is a supervised learning method that does not increase communication overhead for participating parties. It addresses the issue of significant differences between models after the attack has ceased, which can lead to conflicts between backdoor and clean parameters, thereby reducing durability. Furthermore, this invention is based solely on publicly available information and does not interfere with the training of other legitimate clients, thereby enhancing the feasibility of image backdoor attack methods. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 This is a flow chart of the image classification method for backdoor attack of the present invention;
[0050] Figure 2 This is a flow chart of a backdoor attack performed by the backdoor client of the present invention;
[0051] Figure 3 This is a graph showing the improvement of the image classification method for backdoor attacks in the present invention. DETAILED DESCRIPTION
[0052] In this embodiment, an image classification method in a backdoor attack scenario based on federated learning is applied to a central server, Normal clients and In a network environment consisting of backdoor clients, the central server stores a test image dataset with labels. ,in, For the test images, , C is the total number of test images, Normal clients and Each backdoor client stores a local image dataset with labels, K is Normal clients and The total number of local images of each backdoor client; The local labeled private image dataset of a normal client is denoted as ,in, For the The first of the normal clients local images, for 's label; The local labeled private image dataset of the backdoor client is denoted as ,in, For the The backdoor client stores local images, for Category labels; such as Figure 1As shown in the figure, the basic idea is to optimize the triggers during the training of the federated learning image classification model to constrain the distance between the backdoor client's image classification model and the global image classification model, making the backdoor client's image classification model more "similar" to the normal client, thereby evading the federated defense method and improving the backdoor classification effect of the image. The backdoor attack method includes the following steps:
[0053] Step 1. Define the current round as ,initialization ,definition For the serial number of any normal client, define is the serial number of any backdoor client, , ;
[0054] Definition A normal client The gradient of the local image classification model is , No. Backdoor client The gradient of the local image classification model is ;
[0055] Assume that from The backdoor attack starts in round 1, defining the central server in the first The gradient of the image classification model under the backdoor attack is , define The trigger of the wheel is .
[0056] Step 2. Define the central server Distribute to Normal clients and A backdoor client is initialized , .
[0057] Step 3. For the specific process of backdoor client, please refer to Figure 2 , No. Backdoor client exploit For local labeled private image data After processing, enter Backdoor Client The first round of local image classification model Rounds of gradient-free descent training to optimize , thus obtaining the Wheel trigger ;
[0058] Step 3.1. Using Wheel trigger For the kth image sample Perform preprocessing to obtain the kth image sample after preprocessing , After preprocessing, local images, and ; express , and , is the backdoor target label.
[0059] Step 3.2. A backdoor client will Enter Backdoor client The first round of local image classification model is processed, and the formula (1) is used to obtain Wheel trigger ;
[0060] (1)
[0061] In formula (1), ψ is a hyperparameter, for norm; is the optimization function;
[0062] Step 4. Backdoor client exploit right After processing, enter Backdoor client The first round of local image classification model Round of gradient descent training, get the Wheel gradient ;
[0063] Step 4.1. Use formula (2) to After processing, the first images , thus obtaining a local labeled and preprocessed private image dataset ;
[0064] (2)
[0065] Step 4.2. Define the total number of rounds of local training as , the current round of local training is ,initialization , initialize the Backdoor client The local image classification model is Gradients of local training rounds .
[0066] definition For the The backdoor client is in The distance objective function of the local training round is initialized =0;
[0067] The first Image classification model gradient of the central server After the multidimensional vector of the corresponding image classification model is expanded in one dimension, the absolute values of the vector parameters are obtained and then sorted in ascending order. The first several vector parameters are selected and their corresponding positions in the image classification model are recorded as 1, and the remaining positions are marked as 0, thereby obtaining the gradient mask of the image classification model. .
[0068] Step 4.3. The backdoor client uses formula (3) to The local image classification model performs the e-th round of local training and obtains the Backdoor client The local image classification model is Gradients of local training rounds :
[0069] (3)
[0070] In formula (3), For the Backdoor client Gradients of the local image classification model exist On the first The gradient descent function during round training, For the Backdoor client Gradients of the local image classification model In local dataset On the first The gradient descent function during round training, ρ represents the hyperparameter.
[0071] Step 4.4. Calculate the first Backdoor client The local image classification model is +1 round of local training on the target distance function ;
[0072] (4)
[0073] In formula (4), For the Backdoor client Gradients of the local image classification model In local dataset On the first The gradient descent function during round training, is the cosine similarity function, For the Backdoor client Gradients of the local image classification model In local dataset On the first The gradient descent function during round training, for norm, , , There are 3 hyper parameters respectively.
[0074] Step 4.5. Assign to Then, return to step 4.3. and execute the steps in sequence until e> So far, the obtained Backdoor client The local image classification model is Gradients of local training rounds Assign to Backdoor client +1 round of gradients for the local image classification model .
[0075] Step 5. A normal client uses the local dataset Input to the local image classification model for the first Round of gradient descent training, get the Wheel gradient ;
[0076] Step 5.1. Initialization , initialize the A normal client The local image classification model is Gradients of local training rounds .
[0077] Step 5.2. A normal client sends the kth image sample Enter A normal client The first round of local image classification model is processed, and the formula (5) is used to classify the The local image classification model is used for the first Round of gradient descent training, get the A normal client The local image classification model is Gradients of local training rounds ;
[0078] (5)
[0079] Step 5.3. Assign to After that, return to step 5.2 and execute sequentially until the maximum round E is reached, so that the gradient of the local E local training is obtained. Assign to A normal client Gradients of the local image classification model .
[0080] Step 6. The central server uses formula (6) to calculate the M normal clients in the first The gradient of the round and M backdoor clients in the first The gradients of the first round are aggregated to obtain Backdoor attack on the gradient of image classification model ;
[0081] (6)
[0082] In formula (6), Represents an aggregate function.
[0083] Step 7. Central server utilizes gradient The corresponding image classification model predicts C test images and obtains +1 round of predicted category labels under C backdoor attacks, thus according to Statistics +1 round of C backdoor attacks in the predicted category labels for the total number of correct predictions , you can use the total To dynamically quantify each The effect of backdoor attacks on image classification.
[0084] Step 8. Assign to After that, return to step 2 and execute sequentially until the maximum number of rounds is reached, thereby obtaining the image classification model under the backdoor attack corresponding to the optimal gradient;
[0085] Step 9. The central server uses the image classification model under the backdoor attack corresponding to the optimal gradient to predict C test images and obtains C predicted category labels under the backdoor attack. The effect is as follows: Figure 3 As shown, compared with common backdoor attacks, the Enhanced-Neurotoxin technology of the present invention can obtain a more persistent and more hidden backdoor when performing image classification. Figure 3 The blue curve represented by Baseline is the effect trend of the common federated backdoor attack technology, and the orange curve represented by Enhanced-Neurotoxin is the effect trend of the technology of this invention. Above the image are three federated aggregation defense methods. ASR represents the success rate of the attack. The bottom Round indicates the current attack round.
[0086] In this embodiment, an electronic device includes a memory and a processor. The memory is used to store a program of the above-mentioned image classification method, and the processor runs the program stored in the memory.
[0087] In this embodiment, a readable storage medium is used to store computer program instructions, and the computer program instructions are read and executed by a processor to perform the steps of the above-mentioned image classification method.
[0088] It should be emphasized that the above embodiments are only preferred embodiments of the present invention and are not intended to limit the present invention. Any changes, modifications and variations made within the essential scope of the present invention should be within the scope of protection of the present invention.
Claims
1. An image classification method based on federated learning in a backdoor attack scenario, characterized by: Applicable to a central server, Normal clients and In a network environment composed of backdoor clients, the central server stores a test image dataset with labels. ,in, For the test images, , C is the total number of test images, Normal clients and Each backdoor client stores a local image dataset with labels, K is Normal clients and The total number of local images of each backdoor client; The local labeled private image dataset of a normal client is denoted as ,in, For the The first of the normal clients local images, for 's label; The local labeled private image dataset of the backdoor client is denoted as ,in, For the The backdoor client stores local images, for Category label; the image backdoor attack method includes the following steps: Step 1. Define the current round as ,initialization ,definition For the serial number of any normal client, define is the serial number of any backdoor client, , ; Definition A normal client The gradient of the local image classification model is , No. Backdoor client The gradient of the local image classification model is ; Assume that from The backdoor attack starts in round 1, defining the central server in the first The gradient of the image classification model under the backdoor attack is , define The trigger of the wheel is ; Step 2. The central server will Distribute to Normal clients and A backdoor client is initialized , ; Step 3. Backdoor client exploit For local labeled private image data After processing, enter Backdoor Client The first round of local image classification model Rounds of gradient-free descent training to optimize , thus obtaining the Wheel trigger ; Step 4. Backdoor client exploit right After processing, enter Backdoor client The first round of local image classification model Round of gradient descent training, get the Wheel gradient ; Step 5. A normal client uses the local dataset The local image classification model Round of gradient descent training, get the Wheel gradient ; Step 6. The central server uses formula (6) to calculate the M normal clients in the first The gradient of the round and M backdoor clients in the first The gradients of the first round are aggregated to obtain Backdoor attack on the gradient of image classification model ; (6) In formula (6), Represents an aggregate function; Step 7. Assign to After that, return to step 2 and execute sequentially until the maximum number of rounds is reached, thereby obtaining the image classification model under the backdoor attack corresponding to the optimal gradient; Step 8. The central server uses the image classification model under the backdoor attack corresponding to the optimal gradient to predict C test images and obtain C predicted category labels under the backdoor attack.
2. The image classification method in a backdoor attack scenario based on federated learning according to claim 1 is characterized in that: The step 3 comprises: Step 3.
1. Using Wheel trigger For the kth image sample Perform preprocessing to obtain the kth image sample after preprocessing , After preprocessing, local images, and ; express Category label of Step 3.
2. A backdoor client will Enter Backdoor client The first round of local image classification model is processed, and the formula (1) is used to obtain Wheel trigger ; (1) In formula (1), ψ is a hyperparameter, for norm; is the optimization function.
3. The image classification method in a backdoor attack scenario based on federated learning according to claim 2 is characterized in that: The step 4 comprises: Step 4.
1. Use formula (2) to After processing, the first images , thus obtaining a local labeled and preprocessed private image dataset ; (2) Step 4.
2. Define the total number of rounds of local training as , the current round of local training is ,initialization , initialize the Backdoor client The local image classification model is Gradients of local training rounds ; definition For the The backdoor client is in The distance objective function of the local training round is initialized =0; The first Wheel Gradient After the multidimensional vector of the corresponding image classification model is expanded in one dimension, the absolute values of the vector parameters are obtained and then sorted in ascending order. The first several vector parameters are selected and their corresponding positions in the image classification model are marked as 1, and the remaining positions are marked as 0, thereby obtaining the gradient mask of the image classification model. ; Step 4.
3. The backdoor client uses formula (3) to The local image classification model performs the e-th round of local training and obtains the Backdoor client The local image classification model is Gradients of local training rounds : (3) In formula (3), For the Backdoor client Gradients of the local image classification model exist On the first The gradient descent function during round training, For the Backdoor client Gradients of the local image classification model In local dataset On the first The gradient descent function during round training, ρ represents the hyperparameter; Step 4.
4. Calculate the first Backdoor client The local image classification model is +1 round of local training on the target distance function ; (4) In formula (4), For the Backdoor client Gradients of the local image classification model In local dataset On the first The gradient descent function during round training, is the cosine similarity function, For the Backdoor client Gradients of the local image classification model In local dataset On the first The gradient descent function during round training, for norm, , , There are 3 hyperparameters respectively; Step 4.
5. Assign to Then, return to step 4.
3. and execute the steps in sequence until e> So far, the obtained Backdoor client The local image classification model is Gradients of local training rounds Assign to Backdoor client +1 round of gradients for the local image classification model .
4. The image classification method in a backdoor attack scenario based on federated learning according to claim 3 is characterized in that: The step 5 comprises: Step 5.
1. Initialization , initialize the A normal client The local image classification model is Gradients of local training rounds ; Step 5.
2. A normal client sends the kth image sample Enter A normal client The first round of local image classification model is processed, and the formula (5) is used to classify the The local image classification model is used for the first Round of gradient descent training, get the A normal client The local image classification model is Gradients of local training rounds ; (5) Step 5.
3. Assign to After that, return to step 5.2 and execute sequentially until the maximum round E is reached, so that the gradient of the local E local training is obtained. Assign to A normal client Gradients of the local image classification model .
5. An electronic device comprising a memory and a processor, characterized in that: The memory is used to store a program that supports the processor to execute the image classification method in the backdoor attack scenario described in any one of claims 1-4, and the processor is configured to execute the program stored in the memory.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the image classification method in any backdoor attack scenario of claims 1-4 are executed.