FedDefender: Client-Side Attack-Tolerant Federated Learning

被引:10
|
作者
Park, Sungwon [1 ]
Han, Sungwon
Wu, Fangzhao [2 ]
Kim, Sundong [3 ]
Zhu, Bin [2 ]
Xie, Xing [2 ]
Cha, Meeyoung [1 ,4 ]
机构
[1] Korea Adv Inst Sci & Technol, Daejeon, South Korea
[2] Microsoft Res Asia, Beijing, Peoples R China
[3] GIST, Gwangju, South Korea
[4] Inst for Basic Sci Korea, Daejeon, South Korea
关键词
Federated Learning; Client-Side Defense; Model Poisoning Attack; Knowledge Distillation; Meta Learning;
D O I
10.1145/3580305.3599346
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated learning enables learning from decentralized data sources without compromising privacy, which makes it a crucial technique. However, it is vulnerable to model poisoning attacks, where malicious clients interfere with the training process. Previous defense mechanisms have focused on the server-side by using careful model aggregation, but this may not be effective when the data is not identically distributed or when attackers can access the information of benign clients. In this paper, we propose a new defense mechanism that focuses on the client-side, called FedDefender, to help benign clients train robust local models and avoid the adverse impact of malicious model updates from attackers, even when a server-side defense cannot identify or remove adversaries. Our method consists of two main components: (1) attack-tolerant local meta update and (2) attack-tolerant global knowledge distillation. These components are used to find noise-resilient model parameters while accurately extracting knowledge from a potentially corrupted global model. Our client-side defense strategy has a flexible structure and can work in conjunction with any existing server-side strategies. Evaluations of real-world scenarios across multiple datasets show that the proposed method enhances the robustness of federated learning against model poisoning attacks.
引用
收藏
页码:1850 / 1861
页数:12
相关论文
共 50 条
  • [1] Client-Side Gradient Inversion Attack in Federated Learning Using Secure Aggregation
    Sun, Yu
    Liu, Zheng
    Cui, Jian
    Liu, Jianhua
    Ma, Kailang
    Liu, Jianwei
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (17): : 28774 - 28786
  • [2] Towards Attack-tolerant Federated Learning via Critical Parameter Analysis
    Han, Sungwon
    Park, Sungwon
    Wu, Fangzhao
    Kim, Sundong
    Zhu, Bin
    Xie, Xing
    Cha, Meeyoung
    2023 IEEE/CVF INTERNATIONAL CONFERENCE ON COMPUTER VISION, ICCV, 2023, : 4976 - 4985
  • [3] FedSC: A federated learning algorithm based on client-side clustering
    Wang, Zhuang
    Liu, Renting
    Xu, Jie
    Fu, Yusheng
    ELECTRONIC RESEARCH ARCHIVE, 2023, 31 (09): : 5226 - 5249
  • [4] Class-Hidden Client-Side Watermarking in Federated Learning
    Chen, Weitong
    Zhang, Chi
    Zhang, Wei
    Cai, Jie
    ENTROPY, 2025, 27 (02)
  • [5] Client-Side Optimization Strategies for Communication-Efficient Federated Learning
    Mills, Jed
    Hu, Jia
    Min, Geyong
    IEEE COMMUNICATIONS MAGAZINE, 2022, 60 (07) : 60 - 66
  • [6] Client-Side Detection of SQL Injection Attack
    Shahriar, Hossain
    North, Sarah
    Chen, Wei-Chuen
    ADVANCED INFORMATION SYSTEMS ENGINEERING WORKSHOPS (CAISE), 2013, 148 : 512 - 517
  • [7] Efficient Federated Learning with Adaptive Client-Side Hyper-Parameter Optimization
    Kundroo, Majid
    Kim, Taehong
    2023 IEEE 43RD INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, ICDCS, 2023, : 973 - 974
  • [8] Confidential Federated Learning for Heterogeneous Platforms against Client-Side Privacy Leakages
    Li, Qiushi
    Zhang, Yan
    PROCEEDINGS OF THE ACM TURING AWARD CELEBRATION CONFERENCE-CHINA 2024, ACM-TURC 2024, 2024, : 239 - 241
  • [9] Watermarking in Secure Federated Learning: A Verification Framework Based on Client-Side Backdooring
    Yang, Wenyuan
    Shao, Shuo
    Yang, Yue
    Liu, Xiyao
    Liu, Ximeng
    Xia, Zhihua
    Schaefer, Gerald
    Fang, Hui
    ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2024, 15 (01)
  • [10] Secure Federated Learning Model Verification: A Client-side Backdoor Triggered Watermarking Scheme
    Liu, Xiyao
    Shao, Shuo
    Yang, Yue
    Wu, Kangming
    Yang, Wenyuan
    Fang, Hui
    2021 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2021, : 2414 - 2419