DefendFL: A Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks

被引:1
|
作者
Liu, Jiao [1 ,2 ,3 ]
Li, Xinghua [1 ,2 ,3 ]
Liu, Ximeng [4 ]
Zhang, Haiyan [1 ,2 ,3 ,4 ]
Miao, Yinbin [1 ,2 ,3 ,4 ]
Deng, Robert H. [5 ]
机构
[1] Xidian Univ, State Key Lab Integrated Serv Networks, Xian 710126, Peoples R China
[2] Xidian Univ, Sch Cyber Engn, Xian 710071, Peoples R China
[3] AV Xian Aeronaut Comp Tech Res Inst, Xian 710068, Peoples R China
[4] Fuzhou Univ, Coll Comp & Data Sci, Fuzhou 350116, Peoples R China
[5] Singapore Management Univ, Sch Informat Syst, Singapore 178902, Singapore
基金
中国国家自然科学基金;
关键词
Federated learning (FL); poisoning attacks; poisoning detection; privacy protection; secure aggregation;
D O I
10.1109/TNNLS.2024.3423397
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning (FL) has become a popular mode of learning, allowing model training without the need to share data. Unfortunately, it remains vulnerable to privacy leakage and poisoning attacks, which compromise user data security and degrade model quality. Therefore, numerous privacy-preserving frameworks have been proposed, among which mask-based framework has certain advantages in terms of efficiency and functionality. However, it is more susceptible to poisoning attacks from malicious users, and current works lack practical means to detect such attacks within this framework. To overcome this challenge, we present DefendFL, an efficient, privacy-preserving, and poisoning-detectable mask-based FL scheme. We first leverage collinearity mask to protect users' gradient privacy. Then, cosine similarity is utilized to detect masked gradients to identify poisonous gradients. Meanwhile, a verification mechanism is designed to detect the mask, ensuring the mask's validity in aggregation and preventing poisoning attacks by intentionally changing the mask. Finally, we resist poisoning attacks by removing malicious gradients or lowering their weights in aggregation. Through security analysis and experimental evaluation, DefendFL can effectively detect and mitigate poisoning attacks while outperforming existing privacy-preserving detection works in efficiency.
引用
收藏
页数:14
相关论文
共 50 条
  • [41] Federated learning for privacy-preserving AI
    Cheng, Yong
    Liu, Yang
    Chen, Tianjian
    Yang, Qiang
    COMMUNICATIONS OF THE ACM, 2020, 63 (12) : 33 - 36
  • [42] Privacy-Preserving and Reliable Federated Learning
    Lu, Yi
    Zhang, Lei
    Wang, Lulu
    Gao, Yuanyuan
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2021, PT III, 2022, 13157 : 346 - 361
  • [43] A blockchain based privacy-preserving federated learning scheme for Internet of Vehicles
    Naiyu Wang
    Wenti Yang
    Xiaodong Wang
    Longfei Wu
    Zhitao Guan
    Xiaojiang Du
    Mohsen Guizani
    Digital Communications and Networks, 2024, 10 (01) : 126 - 134
  • [44] A Privacy-Preserving Aggregation Scheme With Continuous Authentication for Federated Learning in VANETs
    Feng, Xia
    Wang, Xiaofeng
    Liu, Haiyang
    Yang, Haowei
    Wang, Liangmin
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2024, 73 (07) : 9465 - 9477
  • [45] Privacy-Preserving Authenticated Federated Learning Scheme for Smart Healthcare System
    Tu, Jun
    Shen, Gang
    EMERGING INFORMATION SECURITY AND APPLICATIONS, EISA 2023, 2024, 2004 : 38 - 57
  • [46] A blockchain based privacy-preserving federated learning scheme for Internet of Vehicles
    Wang, Naiyu
    Yang, Wenti
    Wang, Xiaodong
    Wu, Longfei
    Guan, Zhitao
    Du, Xiaojiang
    Guizani, Mohsen
    DIGITAL COMMUNICATIONS AND NETWORKS, 2024, 10 (01) : 126 - 134
  • [47] Anonymous and Efficient Authentication Scheme for Privacy-Preserving Federated Cross Learning
    Li, Zeshuai
    Liang, Xiaoyan
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IX, ICIC 2024, 2024, 14870 : 281 - 293
  • [48] A Privacy-Preserving Scheme for Multi-Party Vertical Federated Learning
    FAN Mochan
    ZHANG Zhipeng
    LI Difei
    ZHANG Qiming
    YAO Haidong
    ZTE Communications, 2024, 22 (04) : 89 - 96
  • [49] An effective and verifiable secure aggregation scheme with privacy-preserving for federated learning
    Wang, Rong
    Xiong, Ling
    Geng, Jiazhou
    Xie, Chun
    Li, Ruidong
    JOURNAL OF SYSTEMS ARCHITECTURE, 2025, 161
  • [50] Privacy-Preserving Federated Learning Against Label-Flipping Attacks on Non-IID Data
    Shen, Xicong
    Liu, Ying
    Li, Fu
    Li, Chunguang
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (01): : 1241 - 1255