AIセキュリティポータル K Program
Precision Guided Approach to Mitigate Data Poisoning Attacks in Federated Learning
Share
Abstract
Federated Learning (FL) is a collaborative learning paradigm enabling participants to collectively train a shared machine learning model while preserving the privacy of their sensitive data. Nevertheless, the inherent decentralized and data-opaque characteristics of FL render its susceptibility to data poisoning attacks. These attacks introduce malformed or malicious inputs during local model training, subsequently influencing the global model and resulting in erroneous predictions. Current FL defense strategies against data poisoning attacks either involve a trade-off between accuracy and robustness or necessitate the presence of a uniformly distributed root dataset at the server. To overcome these limitations, we present FedZZ, which harnesses a zone-based deviating update (ZBDU) mechanism to effectively counter data poisoning attacks in FL. Further, we introduce a precision-guided methodology that actively characterizes these client clusters (zones), which in turn aids in recognizing and discarding malicious updates at the server. Our evaluation of FedZZ across two widely recognized datasets: CIFAR10 and EMNIST, demonstrate its efficacy in mitigating data poisoning attacks, surpassing the performance of prevailing state-of-the-art methodologies in both single and multi-client attack scenarios and varying attack volumes. Notably, FedZZ also functions as a robust client selection strategy, even in highly non-IID and attack-free scenarios. Moreover, in the face of escalating poisoning rates, the model accuracy attained by FedZZ displays superior resilience compared to existing techniques. For instance, when confronted with a 50% presence of malicious clients, FedZZ sustains an accuracy of 67.43%, while the accuracy of the second-best solution, FL-Defender, diminishes to 43.36%.
Flap-a federated learning framework for attribute-based access control policies
Amani Abu Jabal, Elisa Bertino, Jorge Lobo, Dinesh Verma, Seraphin Calo, Alessandra Russo
Published: 2023
How to backdoor federated learning
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, Vitaly Shmatikov
Published: 2020
Diverse client selection for federated learning via submodular maximization
Ravikumar Balakrishnan, Tian Li, Tianyi Zhou, Nageen Himayat, Virginia Smith, Jeff Bilmes
Published: 2021
Machine learning with adversaries: Byzantine tolerant gradient descent
Blanchard, P., El Mhamdi, E. M., Guerraoui, R., Stainer, J.
Published: 2017
Prediction of mobile app privacy preferences with user profiles via federated learning
André Brandão, Ricardo Mendes, João P Vilela
Published: 2022
Fltrust: Byzantine-robust federated learning via trust bootstrapping
X. Cao, M. Fang, J. Liu, N. Z. Gong
Published: 2021
A systematic review of fuzzing techniques
Chen Chen, Baojiang Cui, Jinxin Ma, Runpu Wu, Jianchao Guo, Wenqian Liu
Published: 2018
A training-integrity privacy-preserving federated learning scheme with trusted execution environment
Yu Chen, Fang Luo, Tong Li, Tao Xiang, Zheli Liu, Jin Li
Published: 2020
Emnist: Extending mnist to handwritten letters
G. Cohen, S. Afshar, J. Tapson, A. van Schaik
Published: 2017
Label inference attacks against vertical federated learning
C. Fu, X. Zhang, S. Ji, J. Chen, J. Wu, S. Guo, J. Zhou, A. X. Liu, T. Wang
Published: 2022
Communication-efficient learning of deep networks from decentralized data
Clement Fung, Chris JM Yoon, Ivan Besch
Fuzzing: Hack, art, and science
Patrice Godefroid
Published: 2020
Simple black-box adversarial attacks
Guo, C., Gardner, J. R., You, Y., Wilson, A. G., Weinberger, K. Q.
Published: 2019
Siren: Byzantine-robust federated learning via proactive alarming
Hanxi Guo, Hao Wang, Tao Song, Yang Hua, Zhangcheng Lv, Xiulang Jin, Zhengui Xue, Ruhui Ma, Haibing Guan
Published: 2021
Dowsing for Overflows: A Guided Fuzzer to Find Buffer Boundary Violations
Istvan Haller, Asia Slowinska, Matthias Neugschwandtner, Herbert Bos
Published: 2013
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, Jian Sun
Published: 2016
FL-Defender: Combating Targeted Attacks in Federated Learning
Najeeb Jebreel, Josep Domingo-Ferrer
Published: 2022.7.3
Razzer: Finding kernel race bugs through fuzzing
Dae R Jeong, Kyungtae Kim, Basavesh Shivakumar, Byoungyoung Lee, Insik Shin
Published: 2019
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton
Published: 2009
The Impact of Adversarial Attacks on Federated Learning: A Survey
K Naveen Kumar, C Krishna Mohan, Aravind Machiry
Published: 2023
Black-box adversarial attacks in autonomous vehicle technology
K Naveen Kumar, C Vishnu, Reshmi Mitra, C Krishna Mohan
Published: 2020
Defense against backdoor attack in federated learning
Shiwei Lu, Ruihu Li, Wenbin Liu, Xuan Chen
Published: 2022
{MOPT}: Optimized mutation scheduling for fuzzers
Chenyang Lyu, Shouling Ji, Chao Zhang, Yuwei Li, Wei-Han Lee, Yu Song, Raheem Beyah
Published: 2019
ShieldFL: Mitigating model poisoning attacks in privacy-preserving federated learning
Zhuoran Ma, Jianfeng Ma, Yinbin Miao, Yingjiu Li, Robert H Deng
Published: 2022
Fuzzing with data dependency information
Alessandro Mantovani, Andrea Fioraldi, Davide Balzarotti
Published: 2022
Federated learning: a collaborative effort to achieve better medical imaging models for individual sites that have small labelled datasets
Dianwen Ng, Xiang Lan, Melissa Min-Szu Yao, Wing P Chan, Mengling Feng
Published: 2021
FLAME: taming backdoors in federated learning
Thien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame, Helen Mollering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, Azalia Mirhoseini, Shaza Zeitouni, Farinaz Koushanfar, Ahmad-Reza Sadeghi, Thomas Schneider
Published: 2022
Tensorfuzz: Debugging neural networks with coverage-guided fuzzing
Augustus Odena, Catherine Olsson, David Andersen, Ian Goodfellow
Published: 2019
Sageflow: Robust federated learning against both stragglers and adversaries
J. Park, D.-J. Han, M. Choi, J. Moon
Published: 2021
Deep-Sight: Mitigating Backdoor Attacks in Federated Learning Through Deep Model Inspection
P. Rieger, T. D. Nguyen, M. Miettinen, A.-R. Sadeghi
Published: 2022
Token-Level Fuzzing
Christopher Salls, Chani Jindal, Jake Corina, Christopher Kruegel, Giovanni Vigna
Published: 2021
Back to the drawing board: A critical evaluation of poisoning attacks on production federated learning
V. Shejwalkar, A. Houmansadr, P. Kairouz, D. Ramage
Published: 2022
Auror: Defending against poisoning attacks in collaborative deep learning systems
Shen, S., Tople, S., Saxena, P.
Published: 2016
Efficient instrumentation for code coverage testing
Mustafa M Tikir, Jeffrey K Hollingsworth
Published: 2002
Byzantine-robust distributed learning: Towards optimal statistical rates
Yin, D., Chen, Y., Kannan, R., Bartlett, P.
Published: 2018
Curse or redemption? how data heterogeneity affects the robustness of federated learning
Syed Zawad, Ahsan Ali, Pin-Yu Chen, Ali Anwar, Yi Zhou, Nathalie Baracaldo, Yuan Tian, Feng Yan
Published: 2021
Fldetector: Defending federated learning against model poisoning attacks via detecting malicious clients
Z. Zhang, X. Cao, J. Jia, N. Z. Gong
Published: 2022
Share