Federated learning systems face critical security risks from data poisoning attacks, where malicious clients manipulate training data to compromise model integrity. Traditional detection methods focus on isolating clients that frequently deviate from the average weight update across training rounds. Building upon this concept, this paper introduces an advanced detection strategy that identifies malicious clients through the analysis of similarities in their updates rather than deviations from the average. Our method computes the Euclidean distance between clients’ weight updates vectors over the training rounds. If some clients consistently appear in close proximity to each other, beyond a predefined threshold, they are flagged as potentially malicious. This approach not only refines detection by focusing on synchronization patterns among attackers but also enhances the robustness of the federated model against coordinated data poisoning attacks. We demonstrate the efficacy of our detection method through systematic experiments and discuss optimal hyperparameter tuning strategies, offering a significant step forward in securing federated learning environments.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing Security in Federated Learning: Detection of Synchronized Data Poisoning Attacks

  • Dimitrios Anastasiadis,
  • Ioannis Refanidis

摘要

Federated learning systems face critical security risks from data poisoning attacks, where malicious clients manipulate training data to compromise model integrity. Traditional detection methods focus on isolating clients that frequently deviate from the average weight update across training rounds. Building upon this concept, this paper introduces an advanced detection strategy that identifies malicious clients through the analysis of similarities in their updates rather than deviations from the average. Our method computes the Euclidean distance between clients’ weight updates vectors over the training rounds. If some clients consistently appear in close proximity to each other, beyond a predefined threshold, they are flagged as potentially malicious. This approach not only refines detection by focusing on synchronization patterns among attackers but also enhances the robustness of the federated model against coordinated data poisoning attacks. We demonstrate the efficacy of our detection method through systematic experiments and discuss optimal hyperparameter tuning strategies, offering a significant step forward in securing federated learning environments.