Federated Learning (FL) is a privacy-focused revolutionary approach distributed paradigm that supports considerable devices to train a shared model collaboratively without disseminating private local information. While FL offers significant privacy benefits, its decentralized nature exposes it to various security threats. Existing defense mechanisms often struggle to effectively address the diverse range of adversarial attacks that can target FL systems, such as poisoning attacks and model quality issues. To address these challenges, we propose DLShield, which operates at the server level, an approach for defending against dirty label poisoning attacks and detecting low-quality models in FL. DLShield leverages a Gaussian distribution to measure the deviation between legitimate and malicious model parameters, allowing it to accurately distinguish benign models from compromised client models. Additionally, DLShield incorporates a reputation calculation module that allocates reputation ratings to each model according to their performance. Models with low reputation scores are pruned from the aggregation phase, reducing the impact of malicious participants on the overall model quality. The performance of DLShield is evaluated using real-world benchmark datasets under different data distribution scenarios. DLShield consistently achieves significant improvements in all metrics, enhancing global accuracy by 7.5%, source class recall by approximately over 24%, and reducing attack success rate by 22.8%, compared with state-of-the-art defense methods.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

DLShield: A Defense Approach Against Dirty Label Attacks in Heterogeneous Federated Learning

  • K. M. Sameera,
  • M. Abhinav,
  • P. P. Amal,
  • T. Babu Abhiram,
  • Raj K. Abishek,
  • Tomichen Amal,
  • P. Anaina,
  • P. Vinod,
  • Rehiman K. A. Rafidha,
  • Conti Mauro

摘要

Federated Learning (FL) is a privacy-focused revolutionary approach distributed paradigm that supports considerable devices to train a shared model collaboratively without disseminating private local information. While FL offers significant privacy benefits, its decentralized nature exposes it to various security threats. Existing defense mechanisms often struggle to effectively address the diverse range of adversarial attacks that can target FL systems, such as poisoning attacks and model quality issues. To address these challenges, we propose DLShield, which operates at the server level, an approach for defending against dirty label poisoning attacks and detecting low-quality models in FL. DLShield leverages a Gaussian distribution to measure the deviation between legitimate and malicious model parameters, allowing it to accurately distinguish benign models from compromised client models. Additionally, DLShield incorporates a reputation calculation module that allocates reputation ratings to each model according to their performance. Models with low reputation scores are pruned from the aggregation phase, reducing the impact of malicious participants on the overall model quality. The performance of DLShield is evaluated using real-world benchmark datasets under different data distribution scenarios. DLShield consistently achieves significant improvements in all metrics, enhancing global accuracy by 7.5%, source class recall by approximately over 24%, and reducing attack success rate by 22.8%, compared with state-of-the-art defense methods.