CONTRA: Defending Against Poisoning Attacks in Federated Learning

CONTRA: Defending Against Poisoning Attacks in Federated Learning
复制标题

DOI:
10.1007/978-3-030-88418-5_22
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
S. Awan;Bo Luo;Fengjun Li
S. Awan;Bo Luo;Fengjun Li
中科院分区:
其他
文献类型:
--
作者:
S. Awan;Bo Luo;Fengjun Li

文献摘要

相似文献

联合学习(FL)是一种新兴的机器学习范式。利用FL,分布式数据所有者聚合他们的模型更新以协作地训练共享的深度神经网络,同时将训练数据保存在本地。然而,FL对本地数据和训练过程几乎没有控制。因此,它很容易受到中毒攻击,在这种攻击中,恶意或受危害的客户端使用恶意训练数据或本地更新作为攻击向量,对训练好的全局模型进行中毒。此外,在具有非IID数据分布的放大FL系统中,现有检测和防御机制的性能显著下降。在本文中,我们提出了一种名为Contra的防御方案,用于防御FL系统中的中毒攻击,例如标签翻转攻击和后门攻击。Contra实施了一种基于余弦相似度的测量方法来确定每轮局部模型参数的可信度,并实施了一种声誉方案,根据客户每轮的贡献和对全球模型的历史贡献来动态地提升或惩罚个别客户。通过广泛的实验,我们证明了Contra算法在显著降低攻击成功率的同时,实现了与全局模型的高精度。与最先进的(SOTA)防御相比,Contra-A将攻击成功率降低了70%,并将全球模型的性能降级降低了约50%。
Federated learning (FL) is an emerging machine learning paradigm. With FL, distributed data owners aggregate their model updates to train a shared deep neural network collaboratively, while keeping the training data locally. However, FL has little control over the local data and the training process. Therefore, it is susceptible to poisoning attacks, in which malicious or compromised clients use malicious training data or local updates as the attack vector to poison the trained global model. Moreover, the performance of existing detection and defense mechanisms drops significantly in a scaled-up FL system with non-iid data distributions. In this paper, we propose a defense scheme named CONTRA to defend against poisoning attacks, e.g., label-flipping and backdoor attacks, in FL systems. CONTRA implements a cosine-similarity-based measure to determine the credibility of local model parameters in each round and a reputation scheme to dynamically promote or penalize individual clients based on their per-round and historical contributions to the global model. With extensive experiments, we show that CONTRA significantly reduces the attack success rate while achieving high accuracy with the global model. Compared with a state-of-the-art (SOTA) defense, CONTRA reduces the attack success rate by 70% and reduces the global model performance degradation by 50%.