<p>Mobile systems including smartphones and IoT devices generate massive high-value data, while conventional centralized data collection and analysis suffer from security and privacy vulnerabilities. Federated learning, an emerging paradigm in machine learning, collaboratively trains high-performance models via participants sharing local training model updates rather than raw data, thereby preserving the privacy of their local datasets and providing a new approach for the secure extraction of data value in mobile systems. However, malicious participants may inject carefully crafted poisoned samples into their local datasets, with the intent of disrupting the convergence of the global model or inducing targeted misclassification. Consequently, the identification of such malicious participants is of critical importance in federated learning. To address these challenges, this paper proposes a poison-resilient and privacy-preserving federated learning scheme in mobile systems. It not only detects poisoning attacks in both vertical federated learning and horizontal federated learning, but also removes prior assumptions regarding participants’ data distributions and restrictions on the proportion of adversarial participants. In addition, a convergence control parameter is introduced to regulate the model’s convergence rate. The security, privacy correctness, fairness, and robustness of the proposed scheme are formally analyzed and rigorously proven. Extensive experiments are conducted on two classic image classification datasets MNIST and SVHN, under diverse settings where the number of poisoning attackers is either more or less than half of all participants, and the local data of participant follows both IID and Non-IID distributions. Experimental results demonstrate that the proposed scheme can effectively detect malicious poisoning attackers regardless of the proportion of malicious participants and whether the data distribution is IID or Non-IID. Meanwhile, our method achieves fairness and robustness against poisoning attacks.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Poison-Resilient and Privacy-Preserving Federated Learning Scheme in Mobile Systems

  • Quanyu Zhao,
  • Chenrui Gu,
  • Bingbing Jiang,
  • Yuanjian Zhou,
  • Zhengjun Jing

摘要

Mobile systems including smartphones and IoT devices generate massive high-value data, while conventional centralized data collection and analysis suffer from security and privacy vulnerabilities. Federated learning, an emerging paradigm in machine learning, collaboratively trains high-performance models via participants sharing local training model updates rather than raw data, thereby preserving the privacy of their local datasets and providing a new approach for the secure extraction of data value in mobile systems. However, malicious participants may inject carefully crafted poisoned samples into their local datasets, with the intent of disrupting the convergence of the global model or inducing targeted misclassification. Consequently, the identification of such malicious participants is of critical importance in federated learning. To address these challenges, this paper proposes a poison-resilient and privacy-preserving federated learning scheme in mobile systems. It not only detects poisoning attacks in both vertical federated learning and horizontal federated learning, but also removes prior assumptions regarding participants’ data distributions and restrictions on the proportion of adversarial participants. In addition, a convergence control parameter is introduced to regulate the model’s convergence rate. The security, privacy correctness, fairness, and robustness of the proposed scheme are formally analyzed and rigorously proven. Extensive experiments are conducted on two classic image classification datasets MNIST and SVHN, under diverse settings where the number of poisoning attackers is either more or less than half of all participants, and the local data of participant follows both IID and Non-IID distributions. Experimental results demonstrate that the proposed scheme can effectively detect malicious poisoning attackers regardless of the proportion of malicious participants and whether the data distribution is IID or Non-IID. Meanwhile, our method achieves fairness and robustness against poisoning attacks.