{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T04:23:18Z","timestamp":1750220598139,"version":"3.41.0"},"reference-count":36,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2021,10,22]],"date-time":"2021-10-22T00:00:00Z","timestamp":1634860800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"NSFC","doi-asserted-by":"crossref","award":["61772148"],"award-info":[{"award-number":["61772148"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Internet Technol."],"published-print":{"date-parts":[[2022,5,31]]},"abstract":"<jats:p>\n            Edge computing, as a relatively recent evolution of cloud computing architecture, is the newest way for enterprises to distribute computational power and lower repetitive referrals to central authorities. In the edge computing environment, Generative Models (GMs) have been found to be valuable and useful in machine learning tasks such as data augmentation and data pre-processing. Federated learning and distributed learning refer to training machine learning models in the edge computing network. However, federated learning and distributed learning also bring additional risks to GMs since all peers in the network have access to the model under training. In this article, we study the vulnerabilities of federated GMs to data-poisoning-based backdoor attacks via gradient uploading. We additionally enhance the attack to reduce the required poisonous data samples and cope with dynamic network environments. Last but not least, the attacks are formally proven to be stealthy and effective toward federated GMs. According to the experiments, neural backdoors can be successfully embedded by including merely\n            <jats:inline-formula content-type=\"math\/tex\">\n              <jats:tex-math notation=\"TeX\" version=\"MathJax\">5\\%<\/jats:tex-math>\n            <\/jats:inline-formula>\n            poisonous samples in the local training dataset of an attacker.\n          <\/jats:p>","DOI":"10.1145\/3425662","type":"journal-article","created":{"date-parts":[[2021,10,23]],"date-time":"2021-10-23T03:14:43Z","timestamp":1634958883000},"page":"1-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["On the Neural Backdoor of Federated Generative Models in Edge Computing"],"prefix":"10.1145","volume":"22","author":[{"given":"Derui","family":"Wang","sequence":"first","affiliation":[{"name":"Swinburne University of Technology and Data61, CSIRO, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sheng","family":"Wen","sequence":"additional","affiliation":[{"name":"Swinburne University of Technology, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alireza","family":"Jolfaei","sequence":"additional","affiliation":[{"name":"Macquarie University, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad Sayad","family":"Haghighi","sequence":"additional","affiliation":[{"name":"University of Tehran, Tehran, Iran"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Surya","family":"Nepal","sequence":"additional","affiliation":[{"name":"Data61, CSIRO, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang","family":"Xiang","sequence":"additional","affiliation":[{"name":"Swinburne University of Technology, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,10,22]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00041"},{"key":"e_1_3_1_3_2","unstructured":"Eugene Bagdasaryan Andreas Veit Yiqing Hua Deborah Estrin and Vitaly Shmatikov. 2018. How to backdoor federated learning. arxiv:1807.00459 (2018)."},{"key":"e_1_3_1_4_2","unstructured":"Shumeet Baluja and Ian Fischer. 2017. Adversarial transformation networks: Learning to generate adversarial examples. arxiv:1703.09387 (2017)."},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.5555\/3454287.3455062"},{"key":"e_1_3_1_6_2","doi-asserted-by":"crossref","unstructured":"Mounir Bensalem Jasenka Dizdarevi\u0107 and Admela Jukan. 2020. Modeling of deep neural network (DNN) placement and inference in edge computing. arxiv:2001.06901 (2020).","DOI":"10.1109\/ICCWorkshops49005.2020.9145449"},{"key":"e_1_3_1_7_2","volume-title":"Proceedings of the Workshop on Security in Machine Learningcollocated with the 32nd Conference on Neural Information Processing Systems (NeurIPS\u201918)","author":"Bhagoji Arjun Nitin","year":"2018","unstructured":"Arjun Nitin Bhagoji, Supriyo Chakraborty, P. Mittal, and S. Calo. 2018. Model poisoning attacks in federated learning. In Proceedings of the Workshop on Security in Machine Learning (SecML\u201918), collocated with the 32nd Conference on Neural Information Processing Systems (NeurIPS\u201918)."},{"key":"e_1_3_1_8_2","first-page":"634","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Bhagoji Arjun Nitin","year":"2019","unstructured":"Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo. 2019. Analyzing federated learning through an adversarial lens. In Proceedings of the International Conference on Machine Learning. 634\u2013643."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.5555\/3294771.3294783"},{"key":"e_1_3_1_10_2","unstructured":"Joseph Clements and Yingjie Lao. 2018. Hardware trojan attacks on neural networks. arxiv:1806.05768 (2018)."},{"key":"e_1_3_1_11_2","unstructured":"Antonia Creswell Anil A. Bharath and Biswa Sengupta. 2017. Latent poison-adversarial attacks on the latent space. arxiv:1711.02879 (2017)."},{"key":"e_1_3_1_12_2","unstructured":"Wang Derui Chaoran Li Sheng Wen Surya Nepal and Yang Xiang. 2019. Man-in-the-middle attacks against machine learning classifiers via malicious generative models. arxiv:1910.06838 (2019)."},{"key":"e_1_3_1_13_2","unstructured":"Shaohua Ding Yulong Tian Fengyuan Xu Qun Li and Sheng Zhong. 2019. Poisoning Attack on Deep Generative Models in Autonomous Driving. Retrieved September 22 2021 from https:\/\/www.cs.wm.edu\/~liqun\/paper\/securecomm19.pdf."},{"key":"e_1_3_1_14_2","unstructured":"Carl Doersch. 2016. Tutorial on variational autoencoders. arxiv:1606.05908 (2016)."},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/WACV45572.2020.9093393"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489304"},{"key":"e_1_3_1_17_2","unstructured":"Clement Fung Chris J. M. Yoon and Ivan Beschastnikh. 2018. Mitigating Sybils in federated learning poisoning. arxiv:1808.04866 (2018)."},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.5555\/2969033.2969125"},{"key":"e_1_3_1_19_2","unstructured":"Tianyu Gu Brendan Dolan-Gavitt and Siddharth Garg. 2017. BadNets: Identifying vulnerabilities in the machine learning model supply chain. arxiv:1708.06733 (2017)."},{"key":"e_1_3_1_20_2","first-page":"3521","volume-title":"Proceedings of the International Conference on Machine Learning","year":"2018","unstructured":"El Mahdi El Mhamdi, Rachid Guerraoui, and Sebastien Rouault. 2018. The hidden vulnerability of distributed learning in Byzantium. In Proceedings of the International Conference on Machine Learning (ICML\u201918). 3521\u20133530."},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.5555\/3327757.3327767"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00014"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.5555\/3045390.3045555"},{"key":"e_1_3_1_24_2","unstructured":"Tian Li Anit Kumar Sahu Ameet Talwalkar and Virginia Smith. 2019. Federated learning: Challenges methods and future directions. arxiv:1908.07873 (2019)."},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2018.00093"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3286490.3286559"},{"key":"e_1_3_1_28_2","volume-title":"IEEE Transactions on Communications","author":"Samarakoon Sumudu","year":"2019","unstructured":"Sumudu Samarakoon, Mehdi Bennis, Walid Saad, and M\u00e9rouane Debbah. 2019. Distributed federated learning for ultra-reliable low-latency vehicular communications. IEEE Transactions on Communications 68, 2 (2019), 1146\u20131159."},{"key":"e_1_3_1_29_2","doi-asserted-by":"crossref","first-page":"325","DOI":"10.1007\/978-981-13-8715-9_39","volume-title":"ICCCE 2019","author":"Sanghavi Jignyasa","year":"2020","unstructured":"Jignyasa Sanghavi. 2020. Review of smart healthcare systems and applications for smart cities. In ICCCE 2019. Lecture Notes in Electrical Engineering, Vol. 570. Springer, 325\u2013331."},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"e_1_3_1_31_2","unstructured":"Aleksei Triastcyn and Boi Faltings. 2019. Federated generative privacy. arxiv:1910.08385 (2019)."},{"key":"e_1_3_1_32_2","unstructured":"Praneeth Vepakomma Otkrist Gupta Tristan Swedish and Ramesh Raskar. 2018. Split learning for health: Distributed deep learning without sharing raw patient data. arxiv:1812.00564 (2018)."},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377454"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.5555\/3304222.3304312"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"e_1_3_1_37_2","first-page":"5650","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Yin Dong","year":"2018","unstructured":"Dong Yin, Yudong Chen, Ramchandran Kannan, and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In Proceedings of the International Conference on Machine Learning (ICML\u201918). 5650\u20135659."}],"container-title":["ACM Transactions on Internet Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3425662","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3425662","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:31:55Z","timestamp":1750195915000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3425662"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,22]]},"references-count":36,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2022,5,31]]}},"alternative-id":["10.1145\/3425662"],"URL":"https:\/\/doi.org\/10.1145\/3425662","relation":{},"ISSN":["1533-5399","1557-6051"],"issn-type":[{"type":"print","value":"1533-5399"},{"type":"electronic","value":"1557-6051"}],"subject":[],"published":{"date-parts":[[2021,10,22]]},"assertion":[{"value":"2020-07-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-10-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}