Bozhong Chen

dblp:184/7487 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
4since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 4 since 2021
YearPublicationVenuePosition
2024 Feature Distraction Based Backdoor Defense for Federated Trained Intrusion Detection System
abstract
Convolutional Neural Network (CNN)-based Intrusion Detection System (IDS) incorporated with Federated Learning (FL) facilitates collaborative model training to secure user privacy and enhance data diversity, emerging as a promising solution to defend malicious flows. Yet, FL is vulnerable to trigger backdoor attacks. Existing methods have limited ability on IDS with FL for detecting or repairing a converged attacked model as they either require access to the training process or are dedicated to specific applications. To tackle the limitations, we propose a novel Features Distraction Defense Framework (FDDF) that does not interfere with the model training and requires only a few additional model inferences to protect users from the aforesaid attack. The experiment results show that FDDF can recover the accuracy effectively and preserve the accuracy of normal models.
Bo-Hsu Ke, Yen-Xin Wang, Shih-Heng Lin, Ming-Han Tsai, Bozhong Chen, Jian-Jhih Kuo, Ren-Hung Hwang
GLOBECOM6
2024 Near-Optimal UAV Deployment for Delay-Bounded Data Collection in IoT Networks
abstract
The rapid growth of Internet of Things (IoT) applications has spurred the need for efficient data collection mechanisms. Traditional approaches relying on fixed infrastructure have limitations in coverage, scalability, and deployment costs. Unmanned Aerial Vehicles (UAVs) have emerged as a promising alternative due to their mobility and flexibility. In this paper, we aim to minimize the number of UAVs deployed to collect data in IoT networks while considering a delay budget for energy limitation and data freshness. To this end, we propose a novel 3-approximation dynamic-programming-based algorithm called GPUDA to address the challenges of efficient data collection from IoT devices via UAVs for real-world scenarios where the number of UAVs owned by an individual or organization is unlikely to be excessive, improving the best-known approximation ratio of 4. GPUDA is a geometric partition-based method that incorporates data rounding techniques. The experimental results demonstrate that the proposed algorithm requires 35.01% to 58.55% fewer deployed UAVs than the existing algorithms on average.
Shu-Wei Chang, Jian-Jhih Kuo, Mong-Jen Kao, Bozhong Chen, Qian-Jing Wang
INFOCOM4
2023 Knowledge Distillation Based Defense for Audio Trigger Backdoor in Federated Learning
abstract
The applications of Automatic Speech Recognition (ASR) on Internet-of-Things (IoT) devices have increased significantly in recent years, and Federated Learning (FL) is often used to improve ASR performance since its decentralized training mechanism ensures users' data privacy. However, FL is vulnerable to various attacks. The most challenging one to detect and defend against is trigger backdoor attack. Adversaries inject the trigger into the training audio data and participate in the FL training, causing the converged global model to mispredict the poisoned data. Unlike previous defense methods filtering suspicious models during model aggregation, we propose the Knowledge Distillation Defense Framework (KDDF) to detect and remove features of the potential triggers during the inference. KDDF utilizes Knowledge Distillation (KD) to train a validation model on each IoT device, which is used to identify suspicious data. Then, KDDF would try to eliminate the injected trigger during the model inference if the data is suspicious. Experimental results show that KDDF can effectively distinguish between benign and suspicious data and recover the classification results of suspicious data.
Bo-Hsu Ke, Bozhong Chen, Si-Rong Chiu, Chun-Wei Tu, Jian-Jhih Kuo
GLOBECOM3
2023 Successive Interference Cancellation Based Defense for Trigger Backdoor in Federated Learning
abstract
Federated Learning (FL) provides a decentralized training mechanism that ensures users' data privacy. However, FL is vulnerable to backdoor attacks, a type of data poisoning attack. The adversaries tampered with the local models by injecting a trigger into a subset of training data. After the aggregation process, the global model would be poisoned and mispredict the input images that injected a trigger designed by an adversary. Unlike the existing defense methods attempting to identify and remove the abnormal model updates on the aggregation step, this paper proposes a Successive Interference Cancellation-based Defense Framework (SICDF) to detect and eliminate the trigger during model inference. SICDF first employs Explainable AI to infer where the trigger is and then uses image processing skills to eliminate potential trigger effects. Experiment results show that SICDF can effectively recover the poisoned data while only slightly reducing the accuracy of the clean model and benign data.
Bo-Hsu Ke, Bozhong Chen, Si-Rong Chiu, Chun-Wei Tu, Jian-Jhih Kuo
ICC3