Data-Driven Quickest Change Detection for Securing Federated Learning for Internet-of-Vehicles

Data-Driven Quickest Change Detection for Securing Federated Learning for Internet-of-Vehicles
复制标题

DOI:
10.1109/globecom46510.2021.9685333
复制
发表时间:
2021-12
期刊:
2021 IEEE Global Communications Conference (GLOBECOM)
影响因子:
--
通讯作者:
Bimal Ghimire;D. Rawat;A. Rahman
Bimal Ghimire;D. Rawat;A. Rahman
中科院分区:
其他
文献类型:
--
作者:
Bimal Ghimire;D. Rawat;A. Rahman

文献摘要

被引文献

相似文献

由于联合学习固有的隐私保护框架,机器学习(ML)正处于从集中式、分布式向联合学习(FL)过渡的边缘。FL只需与FL服务器交换更新的模型参数即可实现参与者之间的协作学习,同时将训练数据保存在适合于车辆通信的终端设备中。然而,这种学习框架使得服务器的生命周期很难检测到参与者的恶意行为。参与者的恶意模型更新可能会在很大程度上影响学习模型的准确性,从而可能在车联网环境中造成严重后果。为了解决这个问题,我们提出了一种新的方法来将Shiryaev的最快变化检测(QCD)技术应用到FL领域。QCD用于尽快检测FL中模型参数统计特性的异常变化。我们通过两种方式在服务器端应用QCD。首先,应用QCD来检测参与设备发送的模型参数的统计特性的变化。其次,将QCD应用于聚合FL模型参数的历史。第一种方法有助于识别可以在将来的学习活动中消除的恶意客户端。另一种方法帮助服务器在识别聚集FL参数中的异常的情况下回滚到模型的较早版本。由于QCD应用于服务器端,它不会增加客户端的任何计算开销,也不会增加传输过程中被偷听的通信。借助数值结果对这两种方法进行了评价。
Machine Learning (ML) is on the verge of transitioning from centralized, distributed to federated learning (FL) due to the inherent privacy-preserving framework by FL. FL enables collaborative learning among participants just by exchanging updated model parameters with the FL server while keeping training data local in the end devices which is suitable for vehicular communications. However, this learning framework makes the life of the server difficult to detect the malicious behavior of participants. Malicious model updates from participants may affect the accuracy of the learning model considerably and consequently may cause severe consequences in the Internet of Vehicles (IoV) environment. To address this issue, we propose a novel approach to apply Shiryaev's quickest change detection (QCD) technique in the FL realm. QCD is applied to detect abnormal changes in statistical properties of model parameters in FL as quickly as possible. We apply QCD on the server-side in two ways. First, QCD is applied to detect a change in the statistical properties over the model parameters sent by the participating devices. Second, QCD is applied to the history of aggregated FL model parameters. The first approach facilitates identifying malicious clients which can be eliminated in future learning activities. The other approach assists the server to roll back to an earlier version of the model in case of identifying the anomaly in the aggregated FL parameters. As QCD is applied on the server-side, it does not add any computation overhead on the client-side as well as communication overheard during transmission. These two approaches are evaluated with the help of numerical results.