Attack-Resistant Federated Learning with Residual-based Reweighting

Attack-Resistant Federated Learning with Residual-based Reweighting
复制标题

DOI:
--
复制
发表时间:
2019-09
期刊:
ArXiv
影响因子:
--
通讯作者:
Shuhao Fu;Chulin Xie;Bo Li;Qifeng Chen
Shuhao Fu;Chulin Xie;Bo Li;Qifeng Chen
中科院分区:
其他
文献类型:
--
作者:
Shuhao Fu;Chulin Xie;Bo Li;Qifeng Chen

文献摘要

被引文献

相似文献

联邦学习通过利用存储在不同设备上的私有训练数据在多个领域中具有各种应用。然而,联邦学习中的聚合过程非常容易受到对抗性攻击,因此全局模型可能在攻击下表现异常。为了应对这一挑战,我们提出了一种新的聚合算法,基于残差的重新加权,以捍卫联邦学习。我们的聚合算法结合了重复中值回归和迭代加权最小二乘法的加权方案。我们的实验表明,在存在标签翻转、后门和高斯噪声攻击的情况下,我们的聚合算法优于其他替代算法。我们也为我们的聚合算法提供了理论保证。
Federated learning has a variety of applications in multiple domains by utilizing private training data stored on different devices. However, the aggregation process in federated learning is highly vulnerable to adversarial attacks so that the global model may behave abnormally under attacks. To tackle this challenge, we present a novel aggregation algorithm with residual-based reweighting to defend federated learning. Our aggregation algorithm combines repeated median regression with the reweighting scheme in iteratively reweighted least squares. Our experiments show that our aggregation algorithm outperforms other alternative algorithms in the presence of label-flipping, backdoor, and Gaussian noise attacks. We also provide theoretical guarantees for our aggregation algorithm.