Related Experiment Videos
Backspin: A backdoor attack framework for split learning based on smashed data
Zhanyi Hu1, Xuhong Wang2, Cen Chen1
1School of Data Science and Engineering, East China Normal University, No. 3663, North Zhongshan Road, Shanghai, 200062, China.
Summary
Split Learning (SL) is vulnerable to backdoor attacks. A new framework, Backspin, exploits client data similarities to launch effective attacks with minimal impact on clean data accuracy.
Area of Science:
- Cybersecurity
- Machine Learning
Background:
- Split Learning (SL) enables collaborative machine learning for data-private and computationally limited participants.
- While often considered secure, SL faces threats like backdoor attacks, challenging prior assumptions of its resilience.
Purpose of the Study:
- To investigate and demonstrate the vulnerability of Split Learning to backdoor attacks.
- To propose a novel attack framework, Backspin, for executing sophisticated backdoor attacks in SL.
Main Methods:
- Analyzing smashed data from multiple clients to identify vulnerabilities.
- Developing the Backspin framework for both client-side and server-side attacks in SL.
- Evaluating Backspin across Computer Vision (CV) and Natural Language Processing (NLP) tasks on six datasets and six models.
Main Results:
- Backspin achieves an average Attack Success Rate (ASR) exceeding 90%.
- The attack causes a minimal reduction in Clean Data Accuracy (CDA), averaging only 1.5% compared to centralized training.
- Demonstrated effectiveness and robustness against existing privacy defenses in diverse SL settings.
Conclusions:
- Split Learning is susceptible to backdoor attacks, contrary to previous beliefs.
- The Backspin framework presents a potent and balanced method for attacking SL systems without significant performance degradation.