Sybil Attacks and Defense on Differential Privacy based Federated Learning

被引:0
|
作者
Jiang, Yupeng [1 ]
Li, Yong [2 ]
Zhou, Yipeng [1 ]
Zheng, Xi [1 ]
机构
[1] Macquarie Univ, Sydney, NSW, Australia
[2] Changchun Univ Technol, Changchun, Jilin, Peoples R China
基金
澳大利亚研究理事会;
关键词
Federated learning; differential privacy; Sybil attack;
D O I
10.1109/TRUSTCOM53373.2021.00062
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
In federated learning, machine learning and deep learning models are trained globally on distributed devices. The state-of-the-art privacy-preserving technique in the context of federated learning is user-level differential privacy. However, such a mechanism is vulnerable to some specific model poisoning attacks such as Sybil attacks. A malicious adversary could create multiple fake clients or collude compromised devices in Sybil attacks to mount direct model updates manipulation. Recent works on novel defense against model poisoning attacks are difficult to detect Sybil attacks when differential privacy is utilized, as it masks clients' model updates with perturbation. In this work, we implement the first Sybil attacks on differential privacy based federated learning architectures and show their impacts on model convergence. We randomly compromise some clients by manipulating different noise levels reflected by the local privacy budget epsilon of differential privacy with Laplace mechanism on the local model updates of these Sybil clients. As a result, the global model convergence rates decrease or even leads to divergence. We apply our attacks to two recent aggregation defense mechanisms, called Krum and Trimmed Mean. Our evaluation results on the MNIST and CIFAR-10 datasets show that our attacks effectively slow down the convergence of the global models. We then propose a method to keep monitoring the average loss of all participants in each round for convergence anomaly detection and defend our Sybil attacks based on the training loss reported from randomly selected sets of clients as the judging panels. Our empirical study demonstrates that our defense effectively mitigates the impact of our Sybil attacks.
引用
收藏
页码:355 / 362
页数:8
相关论文
共 50 条
  • [41] Secure Federated Learning Scheme Based on Differential Privacy and Homomorphic Encryption
    Zhang, Xuyan
    Huang, Da
    Tang, Yuhua
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT V, ICIC 2024, 2024, 14879 : 435 - 446
  • [42] A Personalized Federated Learning Method Based on Knowledge Distillation and Differential Privacy
    Jiang, Yingrui
    Zhao, Xuejian
    Li, Hao
    Xue, Yu
    ELECTRONICS, 2024, 13 (17)
  • [43] Local Differential Privacy-Based Federated Learning for Internet of Things
    Zhao, Yang
    Zhao, Jun
    Yang, Mengmeng
    Wang, Teng
    Wang, Ning
    Lyu, Lingjuan
    Niyato, Dusit
    Lam, Kwok-Yan
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (11) : 8836 - 8853
  • [44] A Differential Privacy Federated Learning Scheme Based on Adaptive Gaussian Noise
    Jiao, Sanxiu
    Cai, Lecai
    Wang, Xinjie
    Cheng, Kui
    Gao, Xiang
    CMES-COMPUTER MODELING IN ENGINEERING & SCIENCES, 2024, 138 (02): : 1679 - 1694
  • [45] On the Differential Privacy in Federated Learning Based on Over-the-Air Computation
    Park, Sangjun
    Choi, Wan
    IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2024, 23 (05) : 4269 - 4283
  • [46] Research on Federated Learning Data Sharing Scheme Based on Differential Privacy
    Guo, Lihong
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 74 (03): : 5069 - 5085
  • [47] Model poisoning attack in differential privacy-based federated learning
    Yang, Ming
    Cheng, Hang
    Chen, Fei
    Liu, Ximeng
    Wang, Meiqing
    Li, Xibin
    INFORMATION SCIENCES, 2023, 630 : 158 - 172
  • [48] Kalman Filter-Based Differential Privacy Federated Learning Method
    Yang, Xiaohui
    Dong, Zijian
    APPLIED SCIENCES-BASEL, 2022, 12 (15):
  • [49] Preserving Location Privacy in Location Based Services against Sybil Attacks
    Tyagi, Amit Kumar
    Sreenath, N.
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (12): : 189 - 209
  • [50] Privacy-Preserving Federated Learning Resistant to Byzantine Attacks
    Mu X.-T.
    Cheng K.
    Song A.-X.
    Zhang T.
    Zhang Z.-W.
    Shen Y.-L.
    Jisuanji Xuebao/Chinese Journal of Computers, 2024, 47 (04): : 842 - 861