郑州大学学报(理学版)2026,Vol.58Issue(4):19-26,8.DOI:10.13705/j.issn.1671-6841.2024121
基于离散余弦变换的联邦学习后门攻击
Backdoor Attack on Federated Learning Based on Discrete Cosine Transform
摘要
Abstract
Federated learning(FL)is a distributed machine learning approach that allow different partic-ipants to collaboratively train a machine learning model using their respective local datasets.The issues of data silos and user privacy protection can be addressed.However,due to the distributed nature of FL,it was susceptible to backdoor attacks.A backdoor generation scheme,FLDCTBA,utilizing discrete cosine transform(DCT)was proposed.DCT was utilized by this approach to obtain the amplitude and phase spectra of both the original and trigger images.The amplitude spectra of the images were linearly com-bined and then integrated with the phase spectrum of the original image to reconstruct the image via in-verse DCT.Training was conducted on MNIST,Fashion-MNIST,and CIFAR10 datasets,with the data-sets being divided in both independent and identically distributed(IID)and non-independent and identi-cally distributed(non-IID)manners.Compared with pixel backdoor attacks and label flipping attacks,experimental results demonstrated that FLDCTBA could achieve a high attack success rate while maintai-ning the main task accuracy.关键词
联邦学习/后门攻击/离散余弦变换/隐私保护/机器学习Key words
federated learning/backdoor attack/discrete cosine transform/privacy protection/machine learning分类
信息技术与安全科学引用本文复制引用
屈昌盛,陈学斌,任志强,张镇博,李雨欣..基于离散余弦变换的联邦学习后门攻击[J].郑州大学学报(理学版),2026,58(4):19-26,8.基金项目
国家自然科学基金项目(U20A20179) (U20A20179)