Federal learning backdoor attack method and system based on member reasoning

By adopting a backdoor attack method based on member reasoning in federated learning, malicious clients embed local triggers during local training and optimize their member probability, solving the problem that backdoor attacks in the existing technology are difficult to achieve long-term hidden implantation under the federated learning framework, and achieving efficient and hidden backdoor attack effects.

CN119996069AInactive Publication Date: 2025-05-13JINAN UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510436253.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing federated learning backdoor attack methods lack adaptability to model update dynamics, and it is difficult to achieve long-term hidden implantation of backdoors under the federated framework that protects user privacy.

Method used

Using a federated learning backdoor attack method based on member reasoning, by setting up global triggers and decomposing them into local triggers, the malicious client embeds local triggers into normal samples during local training, constructs an attack model to predict the member probability of the sample, and optimizes local triggers to minimize the statistical distribution difference between member probability of the backdoor sample and the normal sample.

Benefits of technology

Backdoor attacks that are dynamically integrated with model training are realized, which improves the success rate and accuracy of the attack, significantly enhances the concealment of the backdoor, and avoids being recognized by the defense mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996069A_ABST
    Figure CN119996069A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of federated learning security, and provides a federated learning backdoor attack method and system based on member reasoning. The method comprises the following steps: setting a global trigger, decomposing the global trigger into a plurality of local triggers, and sending the local triggers to a malicious client one by one; executing federated learning; wherein the malicious client executes the following steps: embedding a local trigger into a normal sample according to a preset poisoning rate to obtain a backdoor sample, executing local training by using a local malicious data set, and sending an update model to the server; constructing an attack model, inputting the backdoors and the normal samples into a current global model to obtain a global confidence vector, and obtaining member probabilities of the backdoors and the normal samples through the attack model; optimizing a local trigger by using the member probability of the backdoor sample with the aim of minimizing the member probability statistical distribution difference of the backdoor and the normal sample; and repeating the local training until a preset training round or model convergence is reached, and completing the backdoor attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of federated learning security technology, and more specifically, to a federated learning backdoor attack method and system based on member reasoning. Background Art

[0002] Federated Learning, as a distributed machine learning framework, achieves data privacy protection and taps into the collaborative value of multi-party data by training global models through multi-client collaboration. It is widely used in finance, medical care, intelligent recommendation and other fields, providing an efficient and compliant solution for cross-institutional data modeling. However, the open nature of federated learning also introduces new security risks, especially malicious clients may tamper with the global model behavior through backdoor attacks, causing the model to output incorrect results under specific trigger conditions, threatening system reliability.

[0003] Traditional backdoor attacks usually use fixed-mode triggers, whose static features are easily identified by anomaly detection mechanisms and are easily invalidated due to parameter averaging during the model aggregation process of federated learning. In addition, existing attack methods lack adaptability to model updates, making it difficult to achieve long-term covert implantation of backdoors under a federated framework that protects user privacy. At present, an adversarial adaptive composite trigger backdoor attack method has been proposed, which introduces adversarial adaptive losses to balance various triggers. In multi-backdoor attacks, triggers can be hidden in triggers in other backdoor tasks to achieve a higher attack success rate. However, there are problems such as low optimization efficiency and significant differences from normal model updates in the optimization of triggers, which results in limited attack success rate and easy interception by defense mechanisms. Therefore, designing a backdoor attack method that is dynamically integrated with model training and difficult to detect under the federated learning framework has become a key challenge to improve system security assessment and defense capabilities. Summary of the invention

[0004] In order to overcome the defects of existing attack methods that lack adaptability to model update dynamics and are difficult to achieve long-term covert implantation of backdoors under a federated framework that protects user privacy, the present invention provides a federated learning backdoor attack method and system based on member reasoning.

[0005] In order to solve the above technical problems, the technical solution of the present invention is as follows: In a first aspect, the present invention proposes a federated learning backdoor attack method based on member reasoning, comprising the following steps: Setting a global trigger, decomposing the global trigger into a plurality of local triggers and sending the local triggers to the malicious client one by one; Perform federated learning; where, for the For each round of local training, the malicious client performs the following steps: The local trigger is embedded into the normal sample according to the preset poisoning rate to obtain the backdoor sample, and after performing local training using the local malicious data set containing the backdoor sample and the normal sample, the updated model is sent to the server; Build an attack model to predict the probability that its input sample belongs to the training set member; Input the backdoor sample and normal sample into the current round The global model is used to obtain the global confidence vector, and then the member probabilities of the backdoor samples and the normal samples are obtained through the attack model; The local trigger is optimized using the member probability of the backdoor sample with the goal of minimizing the difference in member probability statistical distribution between the backdoor sample and the normal sample; Determine whether the preset training round or model convergence has been reached. If not, perform the next round of local training; if so, complete the backdoor attack.

[0006] As a preferred solution, the backdoor sample is composed of the current malicious client Local triggers According to the preset poisoning rate Embedded in local dataset obtained, among which is the sample data, is the original label; the backdoor sample obtained after embedding , the target label is .

[0007] As a preferred solution, the local training is performed using a local malicious data set containing backdoor samples and normal samples, comprising the following steps: using a local malicious data set containing backdoor samples and normal samples Train the local model and minimize the local model training loss function through the gradient descent method to obtain the updated model ; The local model training loss function The expression is:

[0008] in, are the parameters of the current local model; Local malicious data set The number of samples in ; and Represents the local malicious dataset The j samples and labels.

[0009] As a preferred solution, the construction of the attack model includes the following steps: A data set of the same type as the local data set is obtained as an auxiliary data set and used for training a shadow model; the shadow model is a model with a structure and / or parameters similar to the target global model; The trained shadow model is predicted on the local malicious data set to output the shadow confidence vector ; The shadow confidence vector and a label in the local malicious data set used to indicate whether the input sample belongs to the local malicious data set Input the binary classifier and train it with the goal of minimizing the attack loss function to obtain an attack model for predicting the probability that the input sample belongs to a member of the training set. ; The attack loss function The expression is:

[0010] in, are the parameters of the attack model; is the number of samples in the local malicious dataset.

[0011] As a preferred solution, the optimization of the local trigger using the member probability of the backdoor sample includes the following steps: According to the sample membership probability output by the attack model, the backdoor sample membership probability is minimized and the probability of normal sample membership The difference between is taken as the target, and the gradient of the loss function with respect to the trigger parameter is calculated, and the learning rate is used Update local triggers; the updated optimized local triggers are expressed as:

[0012] in, Indicates the current round Malicious clients The local trigger, Represents the updated local trigger applied to the next round of attack; is the gradient with respect to the trigger parameter, represents the loss function of the local trigger.

[0013] As a preferred solution, KL divergence is used to measure the probability of the backdoor sample member and the probability of normal sample membership The difference between them; the expression of the loss function of the local trigger is:

[0014] in, represents the membership probability distribution of the backdoor sample, represents the membership probability distribution of a normal sample; represents the KL divergence function.

[0015] As a preferred solution, the step of sending the updated model to the server further includes the following steps: Sent to the server, the server aggregates all the updated models it receives based on the weighted aggregation method to obtain the updated global model parameters , and sent to each client; its expression is:

[0016] in, Indicates the current round The global model parameters sent by the server in; is a weighted aggregation function, is the number of malicious clients, For Clients The local model update parameters calculated, For Clients The number of samples in the local dataset.

[0017] In a second aspect, the present invention also proposes a federated learning backdoor attack system based on member reasoning, which applies the federated learning backdoor attack method described in the present invention. The system includes: A trigger setting module is used to set a global trigger and decompose the global trigger into local triggers and send them to A malicious client; The central server is used to send the global model parameters to each client, and aggregate and update the updated models returned by each client after completing local training to obtain an updated global model; Client and malicious client, used to perform local training according to the global model parameters sent by the central server; For each round of local training, the malicious client performs the following steps: The local trigger is embedded into the normal sample according to the preset poisoning rate to obtain the backdoor sample, and after performing local training using the local malicious data set containing the backdoor sample and the normal sample, the updated model is sent to the server; Build an attack model to predict the probability that its input sample belongs to the training set member; Input the backdoor sample and normal sample into the current round The global model is used to obtain the global confidence vector, and then the member probabilities of the backdoor samples and the normal samples are obtained through the attack model; The local trigger is optimized using the member probability of the backdoor sample with the goal of minimizing the difference in member probability statistical distribution between the backdoor sample and the normal sample; Determine whether the preset training round or model convergence has been reached. If not, perform the next round of local training; if so, complete the backdoor attack.

[0018] In a third aspect, the present invention further proposes a device comprising a memory and a processor, wherein the memory stores computer-readable instructions, wherein when the computer-readable instructions are executed by the processor, the processor executes all or part of the steps of the federated learning backdoor attack method described in the present invention.

[0019] In a fourth aspect, the present invention further proposes a storage medium on which computer-readable instructions are stored, wherein the computer-readable instructions, when executed by a processor, implement all or part of the steps of the federated learning backdoor attack method as described in the present invention.

[0020] Compared with the prior art, the technical solution of the present invention has the following beneficial effects: During the federated learning training process, the present invention analyzes the output of the global model through member reasoning attack, quantifies the difference in member probability between backdoor samples and normal samples, and further iteratively optimizes local triggers to ensure that the probability distribution of backdoor samples is similar to that of normal samples, thereby realizing a covert backdoor attack. The present invention combines the member reasoning mechanism to improve the success rate and accuracy of distributed backdoor attacks, and adopts a dynamic optimization mechanism to enable the backdoor trigger to be adaptively adjusted, so that the backdoor attack can be continuously effective and difficult to detect during the global model aggregation process, which significantly enhances the concealment of the backdoor and avoids being identified by the defense mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 The figure is a flow chart of a federated learning backdoor attack method according to one embodiment of the present invention.

[0022] Figure 2 The figure is an architecture diagram of a federated learning backdoor attack system according to one embodiment of the present invention. DETAILED DESCRIPTION

[0023] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Instead, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.

[0024] The terms used in the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The singular forms "a", "the" and "the" used in the present invention and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0025] It should be understood that although the terms first, second, third, etc. may be used in the present invention to describe various information, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present invention, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0026] The present invention is described in detail below with reference to the accompanying drawings and specific embodiments.

[0027] Example 1 This embodiment proposes a federated learning backdoor attack method based on member reasoning, such as Figure 1 , which is a flow chart of the member reasoning-based federated learning backdoor attack method of this embodiment.

[0028] The federated learning backdoor attack method based on member reasoning proposed in this embodiment includes the following steps: S100, setting a global trigger, decomposing the global trigger into local triggers and send them to A malicious client; S200, perform federated learning; wherein, for the For each round of local training, the malicious client performs the following steps: S210, embedding the local trigger into the normal sample according to the preset poisoning rate to obtain the backdoor sample, and performing local training using the local malicious data set containing the backdoor sample and the normal sample, and then sending the updated model to the server; S220, constructing an attack model to predict the probability that its input sample belongs to a member of the training set; S230: input the backdoor sample and the normal sample into the current round The global model is used to obtain the global confidence vector, and then the member probabilities of the backdoor samples and the normal samples are obtained through the attack model; S240, optimizing the local trigger using the member probability of the backdoor sample with the goal of minimizing the difference in member probability statistical distribution between the backdoor sample and the normal sample; S300, determining whether the preset training round or model convergence has been reached, if not, executing the next round of local training; if so, completing the backdoor attack.

[0029] In this embodiment, the attacker first designs a global trigger, which is a specific pattern that the attacker wants to embed into the target model, and then decomposes it into multiple local triggers and distributes them to malicious clients to embed in local models to form distributed triggers. During the federated learning training process, the malicious client analyzes the output of the global model through a membership inference attack, quantifies the difference in membership probabilities between backdoor samples and normal samples, and further iterates and optimizes local triggers to ensure that the probability distribution of backdoor samples is similar to that of normal samples, thereby successfully implanting a hidden backdoor.

[0030] This embodiment combines the member reasoning mechanism to improve the success rate and accuracy of distributed backdoor attacks, and adopts a dynamic optimization mechanism to enable the backdoor trigger to be adaptively adjusted, significantly enhancing the concealment of the backdoor and avoiding identification by the defense mechanism, so that the backdoor attack can continue to take effect and be difficult to detect during the global model aggregation process.

[0031] Federated learning is a distributed machine learning technology. Its core idea is to perform distributed model training among multiple data sources with local data. There is no need to exchange local data. Instead, a global model based on virtual fused data is built by exchanging model parameters or intermediate results, thereby achieving a balance between data privacy protection and data sharing computing.

[0032] The backdoor attack based on federated learning is a malicious attack method against the federated learning system. Its core lies in the fact that the attacker takes advantage of the distributed characteristics of federated learning to inject backdoors into the local model training process, thereby affecting the security and reliability of the global model.

[0033] In step S100 of this embodiment, a global trigger is first designed. The trigger is a specific pattern that the attacker wants to embed into the target model. Then, the trigger is decomposed into multiple local triggers and distributed to malicious clients to embed into the local model. At this time, any malicious client will not be directly exposed when uploading the local model update parameters with the backdoor sample embedded in it, which significantly enhances the concealment of the backdoor and avoids being identified by the defense mechanism.

[0034] For example, suppose the global trigger is a dimensional vector or image, set the global trigger to , The dimension of the trigger. Decompose into local triggers and assign them to malicious clients, each malicious client You will get an initial local trigger , which contains part of the global trigger, namely The combination of local triggers eventually forms a global trigger, namely: .

[0035] For example, assume that the global trigger is a 32×32 image that contains a square of a specific color and the rest is random noise. The attacker decomposes the image into four local triggers, which are assigned to four malicious clients. Each local trigger contains a part of the image, so a single malicious client does not directly expose the complete trigger information when uploading its local model update.

[0036] In an optional embodiment, in step S210, the backdoor sample is Malicious Client Local triggers According to the preset poisoning rate Embedded in local dataset obtained, among which is the sample data, is the original label; the backdoor sample obtained after embedding is expressed as , the target label is .

[0037] In this embodiment, each malicious client will assign a local trigger with a poisoning rate of Embedded in local dataset In the example above, we get a local malicious dataset containing backdoor samples and normal samples. , and then, like a benign client, use the dataset to train the local model so that the model exhibits the behavior expected by the attacker when encountering a trigger. With local malicious dataset The number of samples in are equal.

[0038] In an optional embodiment, when performing local training using a local malicious data set containing backdoor samples and normal samples in step S210, the following steps are performed: Exploiting a local malicious dataset containing backdoor samples Train the local model and minimize the local model training loss function through the gradient descent method to obtain the updated model ; The local model training loss function The expression is:

[0039] in, are the parameters of the current local model; For local malicious dataset The number of samples in ; and Represents the local malicious dataset The j samples and labels; is the loss function.

[0040] Among them, the parameters are adjusted according to the gradient, and the update rule is usually: ,in, is a parameter, is the learning rate (step size), is the gradient of the loss function.

[0041] For example, the loss function A cross entropy loss function can be used as an option.

[0042] In this embodiment, the malicious client and the normal client synchronously perform local model training, use the local malicious data set to train the local model to complete training tasks such as image classification, and use the gradient descent method to minimize the local model training loss function to train the local model.

[0043] Further, in an optional embodiment, after sending the updated model to the server in step S210, the following steps are also included: The updated model Sent to the server, the server aggregates all the updated models it receives based on the weighted aggregation method to obtain the updated global model parameters , and sent to each client; its expression is:

[0044] in, Indicates the current round The global model parameters sent by the server in; is a weighted aggregation function, is the number of malicious clients, For Clients The local model update parameters calculated, For Clients The number of samples in the local dataset.

[0045] In this embodiment, the updates of each client are weighted according to the size of its local data set, and the aggregation is completed to obtain a new round of global model , and sent to the client again before the next round of local training until the preset training round is reached.

[0046] In an optional embodiment, in step S220, constructing the attack model includes the following steps: S221. Obtain a data set of the same type as the local data set as an auxiliary data set And used to train the shadow model; and Malicious clients Samples and labels of the auxiliary dataset in ; The shadow model is a model with similar structure and / or parameters to the target global model; S222: Predict the trained shadow model on the local malicious data set and output a shadow confidence vector ; S223: The shadow confidence vector and a label in the local malicious data set used to indicate whether the input sample belongs to the local malicious data set Input into the binary classifier to minimize the attack loss function Train the target to obtain an attack model for predicting the probability that the input sample belongs to the training set member .

[0047] The attack loss function The expression is:

[0048] in, are the parameters of the attack model; is the number of samples in the local malicious dataset.

[0049] For auxiliary datasets ,This embodiment selects a dataset that is similar to the target global model training data, or publicly available and relevant to the target task.

[0050] For example, the target training task is an image classification task, and the CIFAR-10 dataset is selected as the auxiliary dataset. .

[0051] For the shadow model, this embodiment selects a model with similar structure and / or parameters to the target global model to simulate the target global model and train a binary classifier to obtain the probability of predicting the input sample belonging to the training set member. Attack model , which is further used for membership inference attack.

[0052] In an optional embodiment, in step S230, the backdoor sample and normal samples Enter the current round The global model , get the global confidence vector , and then the member probabilities of backdoor samples and normal samples are obtained through the attack model .

[0053] Among them, for the backdoor sample, the confidence vector output by the global model is It is expressed as: ; For normal samples, the confidence vector output by the global model is It is expressed as: .

[0054] Exemplarily, for the confidence vector, the calculation process is: Assume that the target model has categories, input samples After inference of the target model, a confidence vector is output , where each element Represents the model for the sample belong The probability of the class.

[0055] Furthermore, the malicious client converts the global confidence vector Input to the attack model , get the membership probability of backdoor samples and normal samples and .

[0056] In an optional embodiment, in step S240, the local trigger is optimized using the member probability of the backdoor sample with the goal of minimizing the difference in member probability statistical distribution between the backdoor sample and the normal sample, including the following steps: According to the sample membership probability output by the attack model, the backdoor sample membership probability is minimized and the probability of normal sample membership The difference between is taken as the target, and the gradient of the loss function with respect to the trigger parameter is calculated, and the learning rate is used Update the local trigger to make the member probability distribution of the backdoor sample close to that of the normal sample; the updated and optimized local trigger is expressed as:

[0057] in, Indicates the current round Malicious clients The local trigger, Represents the updated local trigger applied to the next round of attack; is the gradient with respect to the trigger parameter, represents the loss function of the local trigger.

[0058] Furthermore, in an optional embodiment, the KL divergence (Kullback-Leibler divergence) is used to measure the probability of the backdoor sample member. and the probability of normal sample membership The difference between them; the expression of the loss function of the local trigger is:

[0059] in, represents the membership probability distribution of the backdoor sample, represents the membership probability distribution of a normal sample; represents the KL divergence function.

[0060] This embodiment uses a membership inference attack to analyze the output of the global model, quantifies the difference in membership probabilities between backdoor samples and normal samples, and further iteratively optimizes local triggers to ensure that the probability distribution of backdoor samples is similar to that of normal samples, thereby successfully implanting a hidden backdoor. In addition, this embodiment uses a dynamic optimization mechanism to enable the backdoor trigger to be adaptively adjusted, significantly enhancing the concealment of the backdoor and preventing it from being identified by the defense mechanism.

[0061] Example 2 This embodiment proposes a federated learning backdoor attack system based on member reasoning, and applies the federated learning backdoor attack method proposed in Example 1. Figure 2 , which is an architecture diagram of the federated learning backdoor attack system of this embodiment.

[0062] The federated learning backdoor attack system based on member reasoning proposed in this embodiment includes: A trigger setting module is used to set a global trigger and decompose the global trigger into local triggers and send them to A malicious client; The central server is used to send the global model parameters to each client, and aggregate and update the updated models returned by each client after completing local training to obtain an updated global model; Client and malicious client, used to perform local training according to the global model parameters sent by the central server; For each round of local training, the malicious client performs the following steps: The local trigger is embedded into the normal sample according to the preset poisoning rate to obtain the backdoor sample, and after performing local training using the local malicious data set containing the backdoor sample and the normal sample, the updated model is sent to the server; Build an attack model to predict the probability that its input sample belongs to the training set member; Input the backdoor sample and normal sample into the current round The global model is used to obtain the global confidence vector, and then the member probabilities of the backdoor samples and the normal samples are obtained through the attack model; The local trigger is optimized using the member probability of the backdoor sample with the goal of minimizing the difference in member probability statistical distribution between the backdoor sample and the normal sample; Determine whether the preset training round or model convergence has been reached. If not, perform the next round of local training; if so, complete the backdoor attack.

[0063] It can be understood that the system of this embodiment corresponds to the method of the above-mentioned embodiment 1, and the options in the above-mentioned embodiment 1 are also applicable to this embodiment, so they will not be described repeatedly here.

[0064] Example 3 This embodiment proposes a computer device, including a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes all or part of the steps of the federated learning backdoor attack method proposed in Example 1.

[0065] Example 4 This embodiment proposes a storage medium on which computer-readable instructions are stored, wherein the computer-readable instructions, when executed by a processor, implement all or part of the steps of the federated learning backdoor attack method proposed in Embodiment 1.

[0066] Exemplarily, the storage medium includes, but is not limited to, a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.

[0067] Exemplarily, the instructions, programs, code sets or instruction sets may be implemented using conventional programming languages.

[0068] Exemplarily, the processor includes but is not limited to a smart phone, a personal computer, a server, a network device, etc., and is used to execute all or part of the steps of the federated learning backdoor attack method described in Example 1.

[0069] Each embodiment of the present invention is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. The device embodiment described above is merely exemplary, in which the modules described as separate components may or may not be physically separated, and the functions of each module can be implemented in the same or one or more software and / or hardware when implementing the scheme of the present invention. It is also possible to select some or all of the modules according to actual needs to achieve the purpose of the scheme of this embodiment.

[0070] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, and are not intended to limit the embodiments of the present invention. For those skilled in the art, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to list all the embodiments here. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the claims of the present invention.

Claims

1. A federated learning backdoor attack method based on member reasoning, characterized in that: The following steps are involved: Setting a global trigger, decomposing the global trigger into a plurality of local triggers and sending the local triggers to the malicious client one by one; Perform federated learning; where, for the For each round of local training, the malicious client performs the following steps: The local trigger is embedded into the normal sample according to the preset poisoning rate to obtain the backdoor sample, and after performing local training using the local malicious data set containing the backdoor sample and the normal sample, the updated model is sent to the server; Build an attack model to predict the probability that its input sample belongs to the training set member; Input the backdoor sample and normal sample into the current round The global model is used to obtain the global confidence vector, and then the member probabilities of the backdoor samples and the normal samples are obtained through the attack model; The local trigger is optimized using the member probability of the backdoor sample with the goal of minimizing the difference in member probability statistical distribution between the backdoor sample and the normal sample; Determine whether the preset training round or model convergence has been reached. If not, perform the next round of local training; if so, complete the backdoor attack.

2. According to claim 1, the federated learning backdoor attack method based on member reasoning is characterized in that: The backdoor sample is currently used by the malicious client Local triggers According to the preset poisoning rate Embedded in local dataset obtained, among which is the sample data, is the original label; the backdoor sample obtained after embedding , the target label is .

3. The method for backdoor attack of federated learning based on member reasoning according to claim 2 is characterized in that: The local training is performed using a local malicious data set containing backdoor samples and normal samples, including the following steps: Utilize a local malicious dataset containing backdoor samples and normal samples Train the local model and minimize the local model training loss function through the gradient descent method to obtain the updated model ; The local model training loss function The expression is: in, are the parameters of the current local model; Local malicious data set The number of samples in ; and Represents the local malicious dataset The j samples and labels.

4. The method for backdoor attack of federated learning based on member reasoning according to claim 1 is characterized in that: The construction of the attack model comprises the following steps: A data set of the same type as the local data set is obtained as an auxiliary data set and used for training a shadow model; the shadow model is a model with a structure and / or parameters similar to the target global model; The trained shadow model is predicted on the local malicious data set to output a shadow confidence vector ; The shadow confidence vector and a label in the local malicious data set used to indicate whether the input sample belongs to the local malicious data set Input the binary classifier and train it with the goal of minimizing the attack loss function to obtain an attack model for predicting the probability that the input sample belongs to a member of the training set. ; The attack loss function The expression is: in, are the parameters of the attack model; is the number of samples in the local malicious dataset.

5. The method for backdoor attack of federated learning based on member reasoning according to claim 1 is characterized in that: The method of optimizing the local trigger by using the member probability of the backdoor sample includes the following steps: According to the sample membership probability output by the attack model, the backdoor sample membership probability is minimized and the probability of normal sample membership The difference between is taken as the target, and the gradient of the loss function with respect to the trigger parameter is calculated, and the learning rate is used Update local triggers; the updated optimized local triggers are expressed as: in, Indicates the current round Malicious clients The local trigger, Represents the updated local trigger applied to the next round of attack; is the gradient with respect to the trigger parameter, represents the loss function of the local trigger.

6. The method for backdoor attack of federated learning based on member reasoning according to claim 5 is characterized in that: Use KL divergence to measure the probability of the backdoor sample member and the probability of normal sample membership The difference between them; the expression of the loss function of the local trigger is: in, represents the membership probability distribution of the backdoor sample, represents the membership probability distribution of a normal sample; represents the KL divergence function.

7. The method for backdoor attack of federated learning based on member reasoning according to any one of claims 1 to 6, characterized in that: The sending of the updated model to the server further includes the following steps: The updated model Sent to the server, the server aggregates all the updated models it receives based on the weighted aggregation method to obtain the updated global model parameters , and sent to each client; its expression is: in, Indicates the current round The global model parameters sent by the server in; is a weighted aggregation function, is the number of malicious clients, For Clients The local model update parameters calculated, For Clients The number of samples in the local dataset.

8. A federated learning backdoor attack system based on member reasoning, applying the federated learning backdoor attack method according to any one of claims 1 to 7, characterized in that: include: A trigger setting module is used to set a global trigger and decompose the global trigger into local triggers and send them to A malicious client; The central server is used to send the global model parameters to each client, and aggregate and update the updated models returned by each client after completing local training to obtain an updated global model; Client and malicious client, used to perform local training according to the global model parameters sent by the central server; For each round of local training, the malicious client performs the following steps: The local trigger is embedded into the normal sample according to the preset poisoning rate to obtain the backdoor sample, and after performing local training using the local malicious data set containing the backdoor sample and the normal sample, the updated model is sent to the server; Build an attack model to predict the probability that its input sample belongs to the training set member; Input the backdoor sample and normal sample into the current round The global model is used to obtain the global confidence vector, and then the member probabilities of the backdoor samples and the normal samples are obtained through the attack model; The local trigger is optimized using the member probability of the backdoor sample with the goal of minimizing the difference in member probability statistical distribution between the backdoor sample and the normal sample; Determine whether the preset training round or model convergence has been reached. If not, perform the next round of local training; if so, complete the backdoor attack.

9. A device comprising a memory and a processor, wherein the memory stores computer-readable instructions, characterized in that: When the computer-readable instructions are executed by the processor, the processor executes all or part of the steps of the federated learning backdoor attack method as described in any one of claims 1 to 7.

10. A storage medium having computer-readable instructions stored thereon, characterized in that: When the computer-readable instructions are executed by a processor, all or part of the steps of the federated learning backdoor attack method as described in any one of claims 1 to 7 are implemented.