DefendFL: A Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks

被引:1
|
作者
Liu, Jiao [1 ,2 ,3 ]
Li, Xinghua [1 ,2 ,3 ]
Liu, Ximeng [4 ]
Zhang, Haiyan [1 ,2 ,3 ,4 ]
Miao, Yinbin [1 ,2 ,3 ,4 ]
Deng, Robert H. [5 ]
机构
[1] Xidian Univ, State Key Lab Integrated Serv Networks, Xian 710126, Peoples R China
[2] Xidian Univ, Sch Cyber Engn, Xian 710071, Peoples R China
[3] AV Xian Aeronaut Comp Tech Res Inst, Xian 710068, Peoples R China
[4] Fuzhou Univ, Coll Comp & Data Sci, Fuzhou 350116, Peoples R China
[5] Singapore Management Univ, Sch Informat Syst, Singapore 178902, Singapore
基金
中国国家自然科学基金;
关键词
Federated learning (FL); poisoning attacks; poisoning detection; privacy protection; secure aggregation;
D O I
10.1109/TNNLS.2024.3423397
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning (FL) has become a popular mode of learning, allowing model training without the need to share data. Unfortunately, it remains vulnerable to privacy leakage and poisoning attacks, which compromise user data security and degrade model quality. Therefore, numerous privacy-preserving frameworks have been proposed, among which mask-based framework has certain advantages in terms of efficiency and functionality. However, it is more susceptible to poisoning attacks from malicious users, and current works lack practical means to detect such attacks within this framework. To overcome this challenge, we present DefendFL, an efficient, privacy-preserving, and poisoning-detectable mask-based FL scheme. We first leverage collinearity mask to protect users' gradient privacy. Then, cosine similarity is utilized to detect masked gradients to identify poisonous gradients. Meanwhile, a verification mechanism is designed to detect the mask, ensuring the mask's validity in aggregation and preventing poisoning attacks by intentionally changing the mask. Finally, we resist poisoning attacks by removing malicious gradients or lowering their weights in aggregation. Through security analysis and experimental evaluation, DefendFL can effectively detect and mitigate poisoning attacks while outperforming existing privacy-preserving detection works in efficiency.
引用
收藏
页数:14
相关论文
共 50 条
  • [21] Federated learning scheme for privacy-preserving of medical data
    Bo W.
    Hongtao L.
    Jie W.
    Yina G.
    Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University, 2023, 50 (05): : 166 - 177
  • [22] An efficient privacy-preserving and verifiable scheme for federated learning
    Yang, Xue
    Ma, Minjie
    Tang, Xiaohu
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 160 : 238 - 250
  • [23] BPFL: Blockchain-based privacy-preserving federated learning against poisoning attack
    Ren, Yanli
    Hu, Mingqi
    Yang, Zhe
    Feng, Guorui
    Zhang, Xinpeng
    INFORMATION SCIENCES, 2024, 665
  • [24] BPFL: Blockchain-based privacy-preserving federated learning against poisoning attack
    Ren, Yanli
    Hu, Mingqi
    Yang, Zhe
    Feng, Guorui
    Zhang, Xinpeng
    Information Sciences, 2024, 665
  • [25] RFed: Robustness-Enhanced Privacy-Preserving Federated Learning Against Poisoning Attack
    Miao, Yinbin
    Yan, Xinru
    Li, Xinghua
    Xu, Shujiang
    Liu, Ximeng
    Li, Hongwei
    Deng, Robert H.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 5814 - 5827
  • [26] Turning Privacy-preserving Mechanisms against Federated Learning
    Arazzi, Marco
    Conti, Mauro
    Nocera, Antonino
    Picek, Stjepan
    PROCEEDINGS OF THE 2023 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, CCS 2023, 2023, : 1482 - 1495
  • [27] ApaPRFL: Robust Privacy-Preserving Federated Learning Scheme Against Poisoning Adversaries for Intelligent Devices Using Edge Computing
    Zuo, Shaojun
    Xie, Yong
    Wu, Libing
    Wu, Jing
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2024, 70 (01) : 725 - 734
  • [28] BPFL: A Blockchain Based Privacy-Preserving Federated Learning Scheme
    Wang, Naiyu
    Yang, Wenti
    Guan, Zhitao
    Du, Xiaojiang
    Guizani, Mohsen
    2021 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2021,
  • [29] FL-PTD: A Privacy Preserving Defense Strategy Against Poisoning Attacks in Federated Learning
    Xia, Geming
    Chen, Jian
    Huang, Xinyi
    Yu, Chaodong
    Zhang, Zhong
    2023 IEEE 47TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE, COMPSAC, 2023, : 735 - 740
  • [30] FVFL: A Flexible and Verifiable Privacy-Preserving Federated Learning Scheme
    Wang, Gang
    Zhou, Li
    Li, Qingming
    Yan, Xiaoran
    Liu, Ximeng
    Wu, Yuncheng
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (13): : 23268 - 23281