Federal learning backdoor attack training method, system and device and medium
By decomposing global triggers into local triggers and optimizing malicious client model parameters, the problems of low obscurity and weak persistence in federated learning backdoor attacks are solved, achieving higher attack accuracy and persistence.
Patent Information
- Application Number
- CN202510754442.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-08-15
AI Technical Summary
The existing federated learning backdoor attack technology has problems such as low concealment and weak durability, which makes the attack effect difficult to maintain for a long time and is easy to detect.
By decomposing global triggers into multiple local triggers and assigning these local triggers to different malicious clients for training, and optimizing the similarity between malicious client model parameters and the Frobenius norm between malicious client and the previous round of global model parameters in each round of training, the stealth and persistence of the attack is enhanced.
It improves the accuracy and durability of backdoor attacks, reduces the impact of benign model parameter dilution on attacks, enhances the concealment of attacks, and solves the problems of low concealment and weak persistence in the existing technology.
Smart Images

Figure CN120498822A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of artificial intelligence security technology, and specifically relates to a federated learning backdoor attack training method, system, equipment and medium. Background Art
[0002] Federated Learning (FL), as a distributed learning paradigm, allows multiple participants to jointly train models without sharing private data, offering the advantage of protecting data privacy. However, due to the distributed nature of FL, it faces various attacks in practical applications, with backdoor attacks being a serious threat. Backdoor attacks embed backdoor triggers in the global model, allowing predefined inputs (backdoor data) to be identified as target categories without affecting the accuracy of the global model's main task. To promote research on FL security and expand its application in a wider range of fields, this paper focuses on backdoor attacks.
[0003] In a federated learning backdoor attack, the central server aggregates the local model parameters of malicious clients and benign clients into a new global model. Since parameter updates to the malicious model can significantly impact the global model, this can cause the accuracy of the global model's main task to suddenly and significantly drop, exposing the attack and reducing its stealth. Once the malicious client ceases the backdoor attack, the accuracy of the backdoor attack will drop significantly as the model parameters of the benign client are aggregated into the global model. This phenomenon is known as the "backdoor persistence problem," meaning that the attack's effectiveness cannot be maintained over the long term, especially as updates to the benign model gradually dilute the impact of the backdoor trigger. Furthermore, existing defense mechanisms (such as the Byzantine Resilient Aggregation Mechanism) can effectively detect and neutralize malicious model updates, which can lead to decreased accuracy in backdoor attacks.
[0004] The paper "Beyond Traditional Threats: A Persistent Backdoor Attack on Federated Learning" (T. Liu et al., "Beyond Traditional Threats: A Persistent Backdoor Attack on Federated Learning," AAAI, vol. 38, no. 19, pp. 21359–21367, Mar. 2024) proposes a distributed backdoor attack method (FCBA). This method decomposes a global trigger into multiple local triggers and assigns these local triggers to different malicious clients in a combined manner. Each malicious client is trained using only a portion of the global trigger, but the aggregated global model is still able to recognize the complete global trigger. This method increases backdoor diversity, prevents dilution by benign model parameters, and enhances the persistence of backdoor attacks. However, when performing a backdoor attack, the accuracy of the main task drops sharply, reducing the stealth of the backdoor attack.
[0005] The paper "Poisoning with Cerberus: Stealthy and Colluded Backdoor Attack against Federated Learning" (X.Lyuet al., "Poisoning with Cerberus: Stealthy and Colluded Backdoor Attack against Federated Learning," AAAI, vol. 37, no. 7, pp. 9020–9028, Jun. 2023) proposes a federated learning backdoor attack scheme (Cerp). By optimizing backdoor triggers and backdoor model parameters, this scheme avoids the significant drop in accuracy of the primary task caused by backdoor attacks. However, after the backdoor attack is terminated, the backdoor updates are quickly diluted by the updates to the benign model, causing the backdoor attack accuracy to drop rapidly, weakening the persistence of the backdoor attack. Summary of the Invention
[0006] In order to overcome the shortcomings of the above-mentioned prior art, the purpose of the present invention is to provide a federated learning backdoor attack training method, system, device and medium. First, a backdoor trigger is generated through a distributed backdoor method, that is, the global trigger is decomposed into multiple local triggers, and these local triggers are distributed to different malicious clients in a combined manner. Each malicious client only uses a part of the global trigger for training, but the final aggregated global model can still recognize the complete global trigger; secondly, in each round of training, through backdoor optimization training, the malicious client reduces the difference between the malicious model and the normal model by optimizing the similarity between multiple malicious model parameters and optimizing the Frobenius norm between the malicious client model parameters and the global model parameters of the previous round, thereby enhancing the concealment of the backdoor attack and solving the problems of low concealment and weak persistence in the backdoor attack scheme in the prior art.
[0007] In order to achieve the above object, the technical solution adopted by the present invention is:
[0008] A federated learning backdoor attack training method, the specific steps are as follows:
[0009] Step 1: Initialize the federated learning system and set the client set S and the malicious client subset Number of training rounds R;
[0010] Step 2: Each client C in the client set S of the federated learning system i ∈S to obtain the original data set D i ;
[0011] Step 3: The attacker uses the original dataset D j The method of using distributed backdoor attack is to attack the malicious client C j ∈S p Constructing a backdoor dataset The rest of the original dataset D j As a clean dataset And set the number of backdoor attack rounds R p ;
[0012] Step 4: During the rth round of training, the central server randomly selects clients to generate a client subset S r , to the client subset S r Each client C i Send global model parameters θ r ;
[0013] Step 5: If client C i ∈S p And the number of training rounds r∈R p , then the client local model is based on the backdoor dataset Backdoor optimization training; otherwise, client C i Based on clean dataset Local training; finally get the local model parameters
[0014] Step 6: The central server aggregates local model parameters Generate global model parameters θ r+1 , then return to step 4 and continue training until r=R.
[0015] The specific method of step 1 is:
[0016] The federated learning system consists of a central server and N clients. The federated learning system is initialized and the full set of clients is set to S = {C1, C2, ..., C i ,…C N}, set the malicious client subset to Where N≥2, 1≤m<N; set the maximum number of communication rounds of federated learning to R, R≥2; set the client C i The number of local iterations is T; the global model parameters of the neural network are initialized to θ°.
[0017] The specific method of step 2 is:
[0018] Each client C i The locally held Z pieces of data X i and its corresponding label Y i Composed of the original data set D i ={X i ,Y i}, where Z ≥ 50, X i ={x i1 ,x i2 ,…,x iz ,…,x iZ}, x iz Represents client C i The zth data held, x iz The corresponding label is y iz .
[0019] The specific method of step 3 is:
[0020] Malicious Client C j Through the distributed backdoor method, the global trigger is divided into l different triggers, and the local trigger is generated through the full combination form, and then the local trigger is generated in the original data set D j In the process, a part of the data set is randomly sampled and injected into the backdoor trigger to generate the backdoor data set. The unsampled part of the data set constitutes a clean data set And set the number of backdoor attack rounds R p .
[0021] The specific method of step 4 is:
[0022] In the rth round of training, the central server randomly selects n clients from the full set of clients S to generate a subset of clients participating in the training S r , and to the client subset S r Each client C i Send the global model parameters θ of round r r .
[0023] The specific method of step 5 is:
[0024] Client subset S r Each client C i Receive global model parameters θ r , using your own original dataset D i Perform local iterative training on the global model. If the client C i ∈S p And the number of training rounds r∈R p , then client C i First calculate the initial model parameters for the current round And calculate the model parameters The cosine similarity f between the model parameters and those of other malicious clients cs , and model parameters and the global model parameters θ of the previous round r-1 The Frobenius norm f between Fro , and according to the Frobenius norm f Fro and cosine similarity f cs To optimize the backdoor trigger of the malicious model; otherwise, client C i Use your own original dataset D i Perform local iterative training on the global model;
[0025] Finally, client C i Get the final local model parameters of round r and will obtain Upload to the central server.
[0026] The specific method of step 6 is:
[0027] The central server receives the local model parameters according to each The global model parameters θ of the next round are generated through the federated averaging algorithm r+1 .
[0028] A federated learning backdoor attack training system, specifically comprising:
[0029] System initialization module: Initialize the federated learning system, set the client set S and the malicious client subset The number of training rounds R, each client C in the client set S i ∈S to obtain the original data set D i ;
[0030] Federated learning backdoor trigger generation module: The attacker generates a trigger based on the original dataset D j The method of using distributed backdoor attack is to attack the malicious client C j ∈S p Constructing a backdoor dataset The rest of the original dataset D j As a clean dataset And set the number of backdoor attack rounds R p ;
[0031] Federated learning backdoor optimization training module: During the rth round of training, the central server randomly selects clients to generate a client subset S r , to the client subset S r Each client C i Send global model parameters θ r , if client C i ∈S p And the number of training rounds r∈R p , then the client local model is based on the backdoor dataset Backdoor optimization training; otherwise, client C i Based on clean dataset Local training; finally get the local model parameters Central server aggregates local model parameters Generate global model parameters θ r+1 , repeat the training until r=R and the training ends.
[0032] A federated learning backdoor attack training device, comprising:
[0033] memory for storing computer programs;
[0034] A processor is configured to implement the federated learning backdoor attack training method when executing the computer program, thereby achieving simultaneous improvement in the concealment and persistence of federated learning backdoor attacks.
[0035] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a federated learning backdoor attack training method.
[0036] Compared with the prior art, the present invention has the following beneficial effects:
[0037] (1) The backdoor trigger generation method of the present invention decomposes the global trigger into local triggers. Each malicious client uses only a part of the global trigger for training, which enhances the diversity of the backdoor triggers and makes it difficult for the malicious model parameters to be diluted by the benign model parameters, effectively improving the accuracy of the backdoor attack and enhancing the persistence of the backdoor attack.
[0038] (2) The backdoor optimization training proposed in the present invention can make it difficult for the robust aggregation rule to detect triggers by increasing the similarity between different malicious client models and reducing the Frobenius norm between the malicious model and the global model when the malicious client is in the attack round, thereby effectively improving the concealment of the backdoor attack.
[0039] In summary, the present invention uses a distributed backdoor approach to decompose a global trigger into multiple local triggers and assign these local triggers to different malicious clients. Each malicious client uses only a portion of the global trigger for training, but the final aggregated global model is still able to recognize the complete global trigger. Through backdoor optimization training, the similarity between the model parameters of the malicious client and the Frobenius norm between the malicious client and the global model parameters of the previous round are optimized in each training round, enhancing the stealthiness of the backdoor attack. This solves the problems of low stealth and weak persistence in existing backdoor attack schemes. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 A schematic diagram of the implementation flow of the federated learning backdoor attack training method provided in an embodiment of the present invention.
[0041] Figure 2 A schematic diagram of the backdoor optimization training process in the federated learning backdoor attack training method provided in an embodiment of the present invention.
[0042] Figure 3 This is a comparison chart of the main task accuracy between the embodiment of the present invention and FCBA.
[0043] Figure 4 The figure compares the backdoor attack accuracy of the embodiment of the present invention and Cerp. DETAILED DESCRIPTION
[0044] The present invention will be described in detail below with reference to the accompanying drawings.
[0045] See also Figure 1A federated learning backdoor attack training method generates backdoor triggers through a distributed backdoor method, that is, decomposing the global trigger into multiple local triggers, and assigning the local triggers to different malicious clients in a combined manner. Each malicious client only uses a part of the global trigger for training, and the aggregated global model is regarded as carrying the complete global trigger; it includes a backdoor attack optimization algorithm, which optimizes the similarity between the model parameters of the malicious client and the Frobenius norm between the global model parameters of the malicious client and the previous round in each round of training, thereby enhancing the concealment and persistence of the backdoor attack, and achieving the synchronous stability of the federated learning backdoor attack accuracy and the main task accuracy, solving the problem that the existing backdoor attack causes a significant drop in the main task accuracy and the low persistence of the backdoor attack accuracy.
[0046] The specific steps are as follows:
[0047] Step 1: Initialize the federated learning system and set the client set S and the malicious client subset Number of training rounds R;
[0048] The federated learning system consists of a central server and N clients. The federated learning system is initialized and the full set of clients is set to S = {C1, C2, ..., C i ,…C N}, set the malicious client subset to Where N≥2, 1≤m<N; set the maximum number of communication rounds of federated learning to R, R≥2; set the client C i The number of local iterations is T; the global model parameters of the neural network are initialized to θ 0 .
[0049] In this embodiment, the number of federated learning clients N = 100, the number of initial local training iterations T = 6, the maximum number of communication rounds R = 500, and the number of malicious clients m = 14. The residual neural network model initialized by the central server is a classification model. The residual neural network is a convolutional neural network with a depth of 18 layers. Its structure includes an initial convolutional layer, four residual layers (each layer contains 2 BasicBlocks), an output layer, and a fully connected layer. The first residual layer has 32 output channels and 32 input channels, the second residual layer has 64 output channels and 32 input channels, the third residual layer has 128 output channels and 64 input channels, and the fourth residual layer has 256 output channels and 128 input channels. The output layer is an average pooling layer with a pooling window size of 4×4. The fully connected layer has 256 input features and 10 output features, which is the number of categories for the classification task.
[0050] Step 2: Each client C in the client set S of the federated learning systemi ∈S to obtain the original data set D i ;
[0051] Each client C i The locally held Z pieces of data X i and its corresponding label Y i Composed of the original data set D i ={X i ,Y i}, where Z ≥ 50, X i ={x i1 ,x i2 ,…,x iz ,…,x iZ}, x iz Represents client C i The zth data held, x iz The corresponding label is y iz .
[0052] In the present invention, each client C i The Z pieces of data held can be any of image data, audio data, and text data. In this embodiment, the CIFAR-10 dataset is used as the image dataset to train a classification model; CIFAR-10 is a standard image classification dataset widely used in machine learning and computer vision, with a total of 60,000 32×32 color images divided into 10 categories, namely airplanes, cars, birds, cats, deer, dogs, frogs, horses, ships, and trucks. In this embodiment, each client C i Each of them holds 200 different images with true labels Y i Color image X i .
[0053] Step 3: The attacker is based on the original data set D j The method of using distributed backdoor attack is to attack the malicious client C j ∈S p Constructing a backdoor dataset The rest of the original dataset D j As a clean dataset And set the number of backdoor attack rounds R p ;
[0054] Malicious Client C j Through the distributed backdoor method, the global trigger is divided into l different triggers, and the local trigger is generated through the full combination form, and then the local trigger is generated in the original data set D j In the process, a part of the data set is randomly sampled and injected into the backdoor trigger to generate the backdoor data set. The unsampled part of the data set constitutes a clean data set And set the number of backdoor attack rounds R p .
[0055] The specific implementation steps for building a backdoor trigger are:
[0056] A given global flip-flop is divided into l different parts. These parts are considered as units and then local flip-flops are generated by combining them in a fully combinatorial form.
[0057] Note: (1) m ≥ l ≥ 2. l = 1 indicates a centralized attack; l greater than m results in extremely small local trigger points, affecting backdoor efficiency and increasing the strategy computational complexity. (2) An attacker with a specific local trigger only exploits patterns from the relevant area to poison the data.
[0058] Each malicious client receives a unique local trigger. The total number of malicious clients m corresponds to the total number of local triggers LT, which is expressed as:
[0059]
[0060] m=LT=2 l -2
[0061] In this embodiment, the global backdoor trigger is set as four pixels of different colors and positions in the upper left corner of the image, and the colors are red, yellow, blue and green. The global trigger is divided into l=4 different parts, and then 2 4 -2 = 14 different local triggers, so each malicious client will receive a unique local trigger.
[0062] Step 4: During the rth round of training, the central server randomly selects clients to generate a client subset S r , to the client subset S r Each client C i Send global model parameters θ r ;
[0063] In the rth round of training, the central server randomly selects n clients from the full set of clients S to generate a subset of clients participating in the training S r In this embodiment, n=20, and the client subset S r Each client C i Send the global model parameters θ of round r r .
[0064] like Figure 2 As shown, in step 5, if client C i ∈S p And the number of training rounds r∈R p , then the client local model is based on the backdoor dataset Backdoor optimization training; otherwise, client C i Based on clean dataset Local training; finally get the local model parameters
[0065] Client subset S r Each client C i Receive global model parameters θ r , using your own original dataset D i Perform local iterative training on the global model. If the client C i ∈S p And the number of training rounds r∈R p , then client C i First calculate the initial model parameters for the current round And calculate the model parameters The cosine similarity f between the model parameters and those of other malicious clients cs , and model parameters and the global model parameters θ of the previous round r-1 The Frobenius norm f between Fro , and according to the Frobenius norm f Fro and cosine similarity f cs To optimize the backdoor trigger of the malicious model; otherwise, client C i Use your own original dataset D i Perform local iterative training on the global model;
[0066] Finally, client C i Get the final local model parameters for round r and will obtain Upload to the central server.
[0067] The specific implementation steps are:
[0068] (5a) Client subset S r Each client C i The original data set D i As the input of the neural network model, forward propagation is performed. and In the dataset Get each data x i,j The corresponding prediction result y for the tth iteration i,j Otherwise, in the dataset The prediction result is The cross entropy loss function is then used to calculate the loss value of this iteration.
[0069] The calculation formula for the loss value of a malicious client is:
[0070]
[0071] (5b) For the malicious client C in the attack round i , calculate its malicious model through Frobenius norm and normal model The distance between them is given by:
[0072]
[0073] (5c) For the malicious client C in the attack round i , calculate C by cosine similarity i With other malicious models C i' ,C i' ∈S p , the distance between them is:
[0074]
[0075] (5d) For the malicious client C in the attack round i ,Through (5a), (5b), and (5c), the final optimization objective function is calculated and the loss is obtained. The calculation formula is:
[0076]
[0077] (5e) Client C i Through loss Taking partial derivatives of local model parameters And according to Update the local model parameters to obtain the local model of round r, where the update formula is:
[0078]
[0079] Where η represents the learning rate;
[0080] (5f) Each client will local model parameters Upload to the central server.
[0081] Step 6: The central server aggregates local model parameters Generate global model parameters θ r+1 , then return to step 4 and continue training until r=R.
[0082] The central server receives the local model parameters according to each The global model parameters θ of the next round are generated through the federated averaging algorithm r+1, the calculation formula is:
[0083]
[0084] A federated learning backdoor attack training system, specifically comprising:
[0085] System initialization module: Initialize the federated learning system, set the client set S and the malicious client subset The number of training rounds R, each client C in the client set S i ∈S to obtain the original data set D i , used to implement steps 1 to 2 of the training method of the present invention;
[0086] Federated learning backdoor trigger generation module: The attacker generates a trigger based on the original dataset D j The method of using distributed backdoor attack is to attack the malicious client C j ∈S p Constructing a backdoor dataset The rest of the original dataset D j As a clean dataset And set the number of backdoor attack rounds R p , used to implement step 3 of the training method of the present invention;
[0087] Federated learning backdoor optimization training module: During the rth round of training, the central server randomly selects clients to generate a client subset S r , to the client subset S r Each client C i Send global model parameters θ r , if client C i ∈S p And the number of training rounds r∈R p , then the client local model is based on the backdoor dataset Backdoor optimization training; otherwise, client C i Based on clean dataset Local training; finally get the local model parameters Central server aggregates local model parameters Generate global model parameters θ r+1 , repeat the training until r=R and end the training, which is used to implement steps 4 to 6 of the training method of the present invention.
[0088] A federated learning backdoor attack training device, comprising:
[0089] memory for storing computer programs;
[0090] A processor is configured to implement the federated learning backdoor attack training method when executing the computer program, thereby achieving simultaneous improvement in the concealment and persistence of federated learning backdoor attacks.
[0091] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a federated learning backdoor attack training method.
[0092] Experimental analysis
[0093] The present invention conducts simulation experiments based on the above examples. The experimental equipment is: CPU is 13900KF, GPU is nvidia4080; experimental parameters: data set is cifar10, model is resnet-18, the total number of clients is 100, of which the number of malicious clients is 14, and the number of clients selected for each round of training is 20; the experimental results are as follows Figure 3 、 Figure 4 shown. Figure 3 This is the Main Task Accuracy (MTA) experiment of federated learning backdoor attack. The red curve in the figure is the result of the solution of the present invention, and the green curve is the existing FCB A solution. Figure 3 It can be clearly seen that when a backdoor attack is carried out, the accuracy drop of the main task of this scheme is significantly smaller than that of the FCBA scheme, which shows that the concealment of the present invention is strong. Figure 4 This is the Attack Success Rate (ASR) experiment of the federated learning backdoor attack. The red curve in the figure is the result of the solution of the present invention, and the green curve is the existing Cerp solution. Figure 4 It can be seen that after the backdoor attack is completed, the present invention still maintains a high backdoor attack accuracy within 150 rounds, while the backdoor attack accuracy of the Cerp scheme drops to 0 in a short period of time, which proves that the present scheme has high durability.
Claims
1. A federated learning backdoor attack training method, characterized in that: The specific steps are as follows: Step 1: Initialize the federated learning system and set the client set S and the malicious client subset Number of training rounds R; Step 2: Each client C in the client set S of the federated learning system i ∈S to obtain the original data set D i ; Step 3: The attacker uses the original dataset D j The method of using distributed backdoor attack is to attack the malicious client C j ∈S p Constructing a backdoor dataset The rest of the original dataset D j As a clean dataset And set the number of backdoor attack rounds R p ; Step 4: During the rth round of training, the central server randomly selects clients to generate a client subset S r , to the client subset S r Each client C i Send global model parameters θ r ; Step 5: If client C i ∈S p And the number of training rounds r∈R p , then the client local model is based on the backdoor dataset Backdoor optimization training; Otherwise, client C i Based on clean dataset Local training; finally get the local model parameters Step 6: The central server aggregates local model parameters Generate global model parameters θ r+1 , then return to step 4 and continue training until r=R.
2. The training method according to claim 1, characterized in that The specific method of step 1 is: The federated learning system consists of a central server and N clients. The federated learning system is initialized and the full set of clients is set to S = {C1, C2, ..., C i ,…C N }, set the malicious client subset to Where N≥2, 1≤m<N; set the maximum number of communication rounds of federated learning to R, R≥2; set the client C i The number of local iterations is T; the global model parameters of the neural network are initialized to θ 0 .
3. The training method according to claim 1, characterized in that The specific method of step 2 is: Each client C i The locally held Z pieces of data X i and its corresponding label Y i Composed of the original data set D i ={X i ,Y i }, where Z ≥ 50, X i ={x i1 ,x i2 ,…,x iz ,…,x iZ }, x iz Represents client C i The zth data held, x iz The corresponding label is y iz .
4. The training method according to claim 1, characterized in that The specific method of step 3 is: Malicious Client C j Through the distributed backdoor method, the global trigger is divided into l different triggers, and the local trigger is generated through the full combination form, and then the local trigger is generated in the original data set D j In the process, a part of the data set is randomly sampled and injected into the backdoor trigger to generate the backdoor data set. The unsampled part of the data set constitutes a clean data set And set the number of backdoor attack rounds R p .
5. The training method according to claim 1, wherein: The specific method of step 4 is: In the rth round of training, the central server randomly selects n clients from the full set of clients S to generate a subset of clients participating in the training S r , and to the client subset S r Each client C i Send the global model parameters θ of round r r .
6. The training method according to claim 1, characterized in that: The specific method of step 5 is: Client subset S r Each client C i Receive global model parameters θ r , using your own original dataset D i Perform local iterative training on the global model. If the client C i ∈S p And the number of training rounds r∈R p , then client C i First calculate the initial model parameters for the current round And calculate the model parameters The cosine similarity f between the model parameters and those of other malicious clients cs , and model parameters and the global model parameters θ of the previous round r-1 The Frobenius norm f between Fro , and according to the Frobenius norm f Fro and cosine similarity f cs To optimize the backdoor trigger of the malicious model; otherwise, client C i Use your own original dataset D i Perform local iterative training on the global model; Finally, client C i Get the final local model parameters of round r and will obtain Upload to the central server.
7. The training method according to claim 1, characterized in that The specific method of step 6 is: The central server receives the local model parameters according to each The global model parameters θ of the next round are generated through the federated averaging algorithm r+1 .
8. A federated learning backdoor attack training system, characterized in that: Specifically include: System initialization module: Initialize the federated learning system, set the client set S and the malicious client subset The number of training rounds R, each client C in the client set S i ∈S to obtain the original data set D i ; Federated learning backdoor trigger generation module: The attacker generates a trigger based on the original dataset D j The method of using distributed backdoor attack is to attack the malicious client C j ∈S p Constructing a backdoor dataset The rest of the original dataset D j As a clean dataset And set the number of backdoor attack rounds R p ; Federated learning backdoor optimization training module: During the rth round of training, the central server randomly selects clients to generate a client subset S r , to the client subset S r Each client C i Send global model parameters θ r , if client C i ∈S p And the number of training rounds r∈R p , then the client local model is based on the backdoor dataset Backdoor optimization training; Otherwise, client C i Based on clean dataset Local training; finally get the local model parameters Central server aggregates local model parameters Generate global model parameters θ r+1 , repeat the training until r=R and the training ends.
9. A federated learning backdoor attack training device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the federated learning backdoor attack training method according to any one of claims 1 to 7 when executing the computer program, thereby achieving simultaneous improvement in the concealment and persistence of federated learning backdoor attacks.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the federated learning backdoor attack training method according to any one of claims 1 to 7 are implemented.