<p>Federated learning is a distributed computing paradigm designed to protect client privacy, enabling multiple clients to collaboratively train a high-performance global model. However, federated learning is vulnerable to targeted poisoning attacks due to its distributed nature. Although existing solutions can effectively mitigate such attacks, they often struggle to handle statistical heterogeneity. Moreover, privacy attacks often coexist with targeted poisoning attacks in federated learning, further increasing the difficulty of defense in distributed computing scenarios. To address the above challenges, this paper proposes a lightweight privacy preserving federated learning framework, named FedSP, to defend against targeted poisoning attacks. The key idea is to design a protocol between two servers to detect and aggregate model updates submitted by clients in a perturbed form. Specifically, we design an adaptive clustering strategy during aggregation to mitigate inconsistencies of model updates caused by statistical heterogeneity. Additionally, we employ a dimensionality reduction to identify a plausible model update, eliminating assumptions regarding the proportion of malicious clients and the root dataset. Theoretical analysis demonstrates the privacy preservation and convergence of FedSP. Compared with the advanced robust federated learning algorithms, experiment results show that FedSP achieves superior performance in defending against targeted poisoning attacks without compromising privacy.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Resisting against targeted poisoning attacks in lightweight privacy preserving federated learning

  • Hongliang Zhang,
  • Haojie Xie,
  • Jiandong Lv

摘要

Federated learning is a distributed computing paradigm designed to protect client privacy, enabling multiple clients to collaboratively train a high-performance global model. However, federated learning is vulnerable to targeted poisoning attacks due to its distributed nature. Although existing solutions can effectively mitigate such attacks, they often struggle to handle statistical heterogeneity. Moreover, privacy attacks often coexist with targeted poisoning attacks in federated learning, further increasing the difficulty of defense in distributed computing scenarios. To address the above challenges, this paper proposes a lightweight privacy preserving federated learning framework, named FedSP, to defend against targeted poisoning attacks. The key idea is to design a protocol between two servers to detect and aggregate model updates submitted by clients in a perturbed form. Specifically, we design an adaptive clustering strategy during aggregation to mitigate inconsistencies of model updates caused by statistical heterogeneity. Additionally, we employ a dimensionality reduction to identify a plausible model update, eliminating assumptions regarding the proportion of malicious clients and the root dataset. Theoretical analysis demonstrates the privacy preservation and convergence of FedSP. Compared with the advanced robust federated learning algorithms, experiment results show that FedSP achieves superior performance in defending against targeted poisoning attacks without compromising privacy.