AIセキュリティポータル K Program
Aggressive or Imperceptible, or Both: Network Pruning Assisted Hybrid Byzantines in Federated Learning
Share
Abstract
Federated learning (FL) has been introduced to enable a large number of clients, possibly mobile devices, to collaborate on generating a generalized machine learning model thanks to utilizing a larger number of local samples without sharing to offer certain privacy to collaborating clients. However, due to the participation of a large number of clients, it is often difficult to profile and verify each client, which leads to a security threat that malicious participants may hamper the accuracy of the trained model by conveying poisoned models during the training. Hence, the aggregation framework at the parameter server also needs to minimize the detrimental effects of these malicious clients. A plethora of attack and defence strategies have been analyzed in the literature. However, often the Byzantine problem is analyzed solely from the outlier detection perspective, being oblivious to the topology of neural networks (NNs). In the scope of this work, we argue that by extracting certain side information specific to the NN topology, one can design stronger attacks. Hence, inspired by the sparse neural networks, we introduce a hybrid sparse Byzantine attack that is composed of two parts: one exhibiting a sparse nature and attacking only certain NN locations with higher sensitivity, and the other being more silent but accumulating over time, where each ideally targets a different type of defence mechanism, and together they form a strong but imperceptible attack. Finally, we show through extensive simulations that the proposed hybrid Byzantine attack is effective against 8 different defence methods.
How to backdoor federated learning
E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, V. Shmatikov
Published: 2020
signsgd with majority vote is communication efficient and fault tolerant
J. Bernstein, J. Zhao, K. Azizzadenesheli, A. Anandkumar
Published: 2019
Analyzing Federated Learning through an Adversarial Lens
Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, Seraphin Calo
Published: 2018.11.30
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, Pavel Laskov
Published: 2012
Machine learning with adversaries: Byzantine tolerant gradient descent
Blanchard, P., El Mhamdi, E. M., Guerraoui, R., Stainer, J.
Published: 2017
Fltrust: Byzantine-robust federated learning via trust bootstrapping
X. Cao, M. Fang, J. Liu, N. Z. Gong
Published: 2021
Distributed training with heterogeneous data: Bridging median- and mean-based algorithms
X. Chen, T. Chen, H. Sun, S. Wu, M. Hong
Published: 2020
Progressive skeletonization: Trimming more fat from a network at initialization
P. de Jorge, A. Sanyal, H. Behl, P. Torr, G. Rogez, P. K. Dokania
Published: 2021
Distributed momentum for byzantine-resilient stochastic gradient descent
E.-M. El-Mhamdi, R. Guerraoui, S. Rouault
Published: 2021
The Hidden Vulnerability of Distributed Learning in Byzantium
El Mahdi El Mhamdi, Rachid Guerraoui, Sébastien Rouault
Published: 2018.2.22
Rigging the lottery: Making all tickets winners
U. Evci, T. Gale, J. Menick, P. S. Castro, E. Elsen
Published: 2020
Local Model Poisoning Attacks to Byzantine-Robust Federated Learning
Minghong Fang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang Gong
Published: 2019.11.27
Share