Secure Federated Training: Detecting Compromised Nodes and Identifying the Type of Attacks

Secure Federated Training: Detecting Compromised Nodes and Identifying the Type of Attacks
复制标题

DOI:
10.1109/icmla55696.2022.00183
复制
发表时间:
2022-12
期刊:
2022 21st IEEE International Conference on Machine Learning and Applications (ICMLA)
影响因子:
--
通讯作者:
Pretom Roy Ovi;A. Gangopadhyay;R. Erbacher;Carl E. Busart
Pretom Roy Ovi;A. Gangopadhyay;R. Erbacher;Carl E. Busart
中科院分区:
其他
文献类型:
--
作者:
Pretom Roy Ovi;A. Gangopadhyay;R. Erbacher;Carl E. Busart

文献摘要

相似文献

联合学习(FL)允许一组客户端在不共享私有数据的情况下协作训练模型。因此,FL对本地数据和相应的训练过程的控制有限。因此,它很容易受到中毒攻击,其中恶意客户端使用恶意训练数据或本地更新来毒害全局模型。在这项工作中,我们首先研究了数据级和模型级中毒攻击。我们通过在每一轮通信期间篡改本地模型更新来模拟模型中毒攻击,并通过在恶意数据上训练一些客户端来模拟数据中毒攻击。在这种攻击下,客户端会将错误的信息传递给服务器,毒化全局模型,并限制其收敛。因此,需要检测受到攻击的客户端以及识别攻击的类型,以将客户端从其恶意状态中恢复。为了解决这些问题,我们提出了一种在联邦框架下的方法,该方法可以检测恶意客户端和攻击类型,同时确保数据隐私。我们的基于聚类的方法利用神经元的激活从本地模型来识别中毒攻击的类型。我们还建议检查参与客户端之间的本地模型更新的权重分布,以检测恶意客户端。我们的实验结果验证了所提出的框架对上述攻击的鲁棒性,成功地检测受损的客户端和攻击类型。此外,由于恶意客户端的存在,在MNIST数据上训练的全局模型即使经过75轮也无法达到最优点,而通过检测恶意客户端,所提出的方法分别在独立同分布(IID)和非独立同分布(non-IID)设置中仅在30轮和40轮内确保收敛。
Federated learning (FL) allows a set of clients to collaboratively train a model without sharing private data. As a result, FL has limited control over the local data and corresponding training process. Therefore, it is susceptible to poisoning attacks in which malicious clients use malicious training data or local updates to poison the global model. In this work, we first studied the data level and model level poisoning attacks. We simulated model poisoning attacks by tampering the local model updates during each round of communication and data poisoning attacks by training a few clients on malicious data. And clients under such attacks carry faulty information to the server, poison the global model, and restrict it from convergence. Therefore, detecting clients under attacks as well as identifying the type of attacks are required to recover the clients from their malicious status. To address these issues, we proposed a way under federated framework that enables the detection of malicious clients and attack types while ensuring data privacy. Our clustering-based approach utilizes the neuron’s activations from the local models to identify the type of poisoning attacks. We also proposed to check the weight distribution of local model updates among the participating clients to detect malicious clients. Our experimental results validated the robustness of the proposed framework against the attacks mentioned above by successfully detecting the compromised clients and the attack types. Moreover, the global model trained on MNIST data couldn’t reach the optimal point even after 75 rounds because of malicious clients, whereas the proposed approach by detecting the malicious clients ensured convergence within only 30 rounds and 40 rounds in independent and identically distributed (IID) and non- independent and identically distributed (non-IID) setup respectively.