{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/backdoor-attack-is-a-devil-in-federated-gan","title":"Backdoor Attack is a Devil in Federated GAN-based Medical Image Synthesis","arxiv_id":"2207.00762","date":"2022-07-02","proceeding":null,"authors":["Ruinan Jin","Xiaoxiao Li"],"abstract":"Deep Learning-based image synthesis techniques have been applied in healthcare research for generating medical images to support open research. Training generative adversarial neural networks (GAN) usually requires large amounts of training data. Federated learning (FL) provides a way of training a central model using distributed data from different medical institutions while keeping raw data locally. However, FL is vulnerable to backdoor attack, an adversarial by poisoning training data, given the central server cannot access the original data directly. Most backdoor attack strategies focus on classification models and centralized domains. In this study, we propose a way of attacking federated GAN (FedGAN) by treating the discriminator with a commonly used data poisoning strategy in backdoor attack classification models. We demonstrate that adding a small trigger with size less than 0.5 percent of the original image size can corrupt the FL-GAN model. Based on the proposed attack, we provide two effective defense strategies: global malicious detection and local training regularization. We show that combining the two defense strategies yields a robust medical image generation.","url_abs":"https://arxiv.org/abs/2207.00762v2","url_pdf":"https://arxiv.org/pdf/2207.00762v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"backdoor-attack-is-a-devil-in-federated-gan","repo_url":"https://github.com/nanboy-ronan/backdoor-fedgan","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"backdoor-attack","task_name":"Backdoor Attack"},{"task_slug":"data-poisoning","task_name":"Data Poisoning"},{"task_slug":"federated-learning","task_name":"Federated Learning"},{"task_slug":"image-generation","task_name":"Image Generation"},{"task_slug":"malicious-detection","task_name":"Malicious Detection"},{"task_slug":"medical-image-generation","task_name":"Medical Image Generation"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2207.00762","atlas_url":"https://app.syntology.ai/?focus=2207.00762","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}