Byzantine-Resilient Differentially Private Federated Learning: A Dual-Phase Group-Wise Aggregation Approach
摘要
Federated learning (FL) enables distributed devices to collaboratively train a machine learning model while keeping their sensitive data private, but it remains vulnerable to Byzantine attacks and privacy threats. While differential privacy (DP) has emerged as a promising technique for safeguarding privacy in FL, its noise introduction weakens defenses against Byzantine attacks, making FL susceptible to adversarial manipulation. Existing solutions attempt to address both privacy and security concerns but often involve modifying DP mechanisms or imposing restrictive assumptions, limiting their practical applicability. To overcome this challenge, we introduce DGShield, a dual-phase group-wise aggregation approach designed to address the dilemma at the group level. First, we propose a deviation-based group formulation method that groups updates based on magnitude deviation. Building on this, we design a group-wise similarity filtering mechanism to reduce noise by leveraging group-level metrics, thereby providing defense against Byzantine attacks at both the magnitude and direction of group-level updates. Experimental results demonstrate that DGShield effectively defends against Byzantine attacks in FL with DP, while also improving accuracy by up to 13% compared to state-of-the-art methods.