FedDefender: Client-Side Attack-Tolerant Federated Learning

被引:10
|
作者
Park, Sungwon [1 ]
Han, Sungwon
Wu, Fangzhao [2 ]
Kim, Sundong [3 ]
Zhu, Bin [2 ]
Xie, Xing [2 ]
Cha, Meeyoung [1 ,4 ]
机构
[1] Korea Adv Inst Sci & Technol, Daejeon, South Korea
[2] Microsoft Res Asia, Beijing, Peoples R China
[3] GIST, Gwangju, South Korea
[4] Inst for Basic Sci Korea, Daejeon, South Korea
关键词
Federated Learning; Client-Side Defense; Model Poisoning Attack; Knowledge Distillation; Meta Learning;
D O I
10.1145/3580305.3599346
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated learning enables learning from decentralized data sources without compromising privacy, which makes it a crucial technique. However, it is vulnerable to model poisoning attacks, where malicious clients interfere with the training process. Previous defense mechanisms have focused on the server-side by using careful model aggregation, but this may not be effective when the data is not identically distributed or when attackers can access the information of benign clients. In this paper, we propose a new defense mechanism that focuses on the client-side, called FedDefender, to help benign clients train robust local models and avoid the adverse impact of malicious model updates from attackers, even when a server-side defense cannot identify or remove adversaries. Our method consists of two main components: (1) attack-tolerant local meta update and (2) attack-tolerant global knowledge distillation. These components are used to find noise-resilient model parameters while accurately extracting knowledge from a potentially corrupted global model. Our client-side defense strategy has a flexible structure and can work in conjunction with any existing server-side strategies. Evaluations of real-world scenarios across multiple datasets show that the proposed method enhances the robustness of federated learning against model poisoning attacks.
引用
收藏
页码:1850 / 1861
页数:12
相关论文
共 50 条
  • [21] Mobile Client-side Personalization
    Asif, Muhammad
    Krogstie, John
    2013 INTERNATIONAL CONFERENCE ON PRIVACY AND SECURITY IN MOBILE SYSTEMS (PRISMS), 2013,
  • [22] Intelligent Client-Side Personalisation
    Clarke, Rebekah Storan
    2017 IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON WEB INTELLIGENCE (WI 2017), 2017, : 1218 - 1221
  • [23] Research on Client-side Defense Techniques of Cross-Site Scripting Attack
    Wang, Xuyang
    Xu, Mingyang
    PROCEEDINGS OF THE 2016 7TH INTERNATIONAL CONFERENCE ON EDUCATION, MANAGEMENT, COMPUTER AND MEDICINE (EMCM 2016), 2017, 59 : 315 - 320
  • [24] Client-Side Application of Deep Learning Models Through Teleradiology
    Jodogn, Sebastien
    CARING IS SHARING-EXPLOITING THE VALUE IN DATA FOR HEALTH AND INNOVATION-PROCEEDINGS OF MIE 2023, 2023, 302 : 997 - 1001
  • [25] An attack-tolerant agreement algorithm for block chain
    Kitakami, Masato
    Matsuoka, Kazuki
    2018 IEEE 23RD PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC), 2018, : 227 - 228
  • [26] Network infiltration with client-side attacks
    Armstrong, Neil
    Network Security, 2007, 2007 (09) : 8 - 10
  • [27] A Client-Side Seat to TLS Deployment
    Birghan, Moritz
    van der Merwe, Thyla
    2022 43RD IEEE SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (SPW 2022), 2022, : 13 - 19
  • [28] An artifact for client-side cryptographic operations
    Portugal, Paulo
    Pazo, Miguel
    Cuno, Alvaro
    Zapata, Fernando
    Saavedra, Ricardo
    2018 37TH INTERNATIONAL CONFERENCE OF THE CHILEAN COMPUTER SCIENCE SOCIETY (SCCC), 2018,
  • [29] Client-side web scripting with HaskellScript
    Meijer, E
    Leijen, D
    Hook, J
    PRACTICAL ASPECTS OF DECLARATIVE LANGUAGES, 1999, 1551 : 196 - 210
  • [30] Client-side Skype Forensics - An Overview
    Meissner, Tina
    Kroeger, Knut
    Creutzburg, Reiner
    MULTIMEDIA CONTENT AND MOBILE DEVICES, 2013, 8667