Lightweight Blockchain-Empowered Secure and Efficient Federated Edge Learning

Lightweight Blockchain-Empowered Secure and Efficient Federated Edge Learning
复制标题

DOI:
10.1109/tc.2023.3293731
复制
发表时间:
2023-11
影响因子:
3.7
通讯作者:
Rui Jin;Jia Hu;Geyong Min;Jed Mills
Rui Jin;Jia Hu;Geyong Min;Jed Mills
中科院分区:
计算机科学2区
文献类型:
--
作者:
Rui Jin;Jia Hu;Geyong Min;Jed Mills

文献摘要

相似文献

联邦学习(FL)已经成为一种保护隐私的分布式机器学习范例,它在不暴露原始数据的情况下,跨多个终端设备(客户端)协作训练共享的全局模型。但是,FL通常假设所有客户机都是良性的,并且信任协调的中央服务器,这对于许多现实场景来说是不现实的。在实践中,客户端可以通过共享有害的模型更新来损害FL进程,而服务器可能出现故障或行为不当。此外,实际应用程序的FL部署受到服务器和客户端之间高通信开销的阻碍,这些客户端通常位于带宽有限的网络边缘。为了解决这些关键挑战,我们提出了一个轻量级的区块链授权安全高效的联邦学习(BEFL)系统。BEFL是通过集成高效通信和相互信息保护的训练方案、基于可验证随机函数(VRF)的经济高效共识机制和支持星际文件系统(IPFS)的可扩展区块链架构而构建的。使用两个基准FL数据集的大量仿真实验表明,BEFL能够抵抗拜占庭客户端发起的数据中毒和模型中毒攻击,对串通恶意区块链节点具有容错性,可扩展到大量区块链节点,并且在网络边缘具有通信效率。
Federated Learning (FL) has emerged as a privacy-preserving distributed Machine Learning paradigm, which collaboratively trains a shared global model across a number of end devices (clients) without exposing their raw data. However, FL typically assumes that all clients are benign and trust the coordinating central server, which is unrealistic for many real-world scenarios. In practice, clients can harm the FL process by sharing poisonous model updates while the server could malfunction or misbehave. Moreover, the deployment of FL for real-world applications is hindered by the high communication overhead between the server and clients that are often at the network edge with limited bandwidth. To address these key challenges, we propose a lightweight Blockchain-Empowered secure and efficient Federated Learning (BEFL) system. BEFL is built by integrating a communication-efficient and mutual-information guarded training scheme, a cost-effective Verifiable Random Function (VRF)-based consensus mechanism, and Inter-Planetary File System (IPFS)-enabled scalable blockchain architecture. Extensive simulation experiments using two benchmark FL datasets demonstrate that BEFL is resistant against byzantine clients launching data poisoning and model poisoning attacks, fault-tolerant against colluded malicious blockchain nodes, scalable to a large number of blockchain nodes, and communication-efficient at the network edge.