Federated learning (FL) enables distributed devices to collaboratively train a machine learning model while keeping their sensitive data private, but it remains vulnerable to Byzantine attacks and privacy threats. While differential privacy (DP) has emerged as a promising technique for safeguarding privacy in FL, its noise introduction weakens defenses against Byzantine attacks, making FL susceptible to adversarial manipulation. Existing solutions attempt to address both privacy and security concerns but often involve modifying DP mechanisms or imposing restrictive assumptions, limiting their practical applicability. To overcome this challenge, we introduce DGShield, a dual-phase group-wise aggregation approach designed to address the dilemma at the group level. First, we propose a deviation-based group formulation method that groups updates based on magnitude deviation. Building on this, we design a group-wise similarity filtering mechanism to reduce noise by leveraging group-level metrics, thereby providing defense against Byzantine attacks at both the magnitude and direction of group-level updates. Experimental results demonstrate that DGShield effectively defends against Byzantine attacks in FL with DP, while also improving accuracy by up to 13% compared to state-of-the-art methods.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Byzantine-Resilient Differentially Private Federated Learning: A Dual-Phase Group-Wise Aggregation Approach

  • Heyi Zhang,
  • Jun Wu,
  • Qianqian Pan

摘要

Federated learning (FL) enables distributed devices to collaboratively train a machine learning model while keeping their sensitive data private, but it remains vulnerable to Byzantine attacks and privacy threats. While differential privacy (DP) has emerged as a promising technique for safeguarding privacy in FL, its noise introduction weakens defenses against Byzantine attacks, making FL susceptible to adversarial manipulation. Existing solutions attempt to address both privacy and security concerns but often involve modifying DP mechanisms or imposing restrictive assumptions, limiting their practical applicability. To overcome this challenge, we introduce DGShield, a dual-phase group-wise aggregation approach designed to address the dilemma at the group level. First, we propose a deviation-based group formulation method that groups updates based on magnitude deviation. Building on this, we design a group-wise similarity filtering mechanism to reduce noise by leveraging group-level metrics, thereby providing defense against Byzantine attacks at both the magnitude and direction of group-level updates. Experimental results demonstrate that DGShield effectively defends against Byzantine attacks in FL with DP, while also improving accuracy by up to 13% compared to state-of-the-art methods.