FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client Perspective

FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client Perspective
复制标题

DOI:
--
复制
发表时间:
2021-10
期刊:
--
影响因子:
--
通讯作者:
Jingwei Sun;Ang Li;Louis DiValentin;Amin Hassanzadeh;Yiran Chen;H. Li
Jingwei Sun;Ang Li;Louis DiValentin;Amin Hassanzadeh;Yiran Chen;H. Li
中科院分区:
其他
文献类型:
--
作者:
Jingwei Sun;Ang Li;Louis DiValentin;Amin Hassanzadeh;Yiran Chen;H. Li

文献摘要

被引文献

相似文献

联合学习(FL)是一种流行的分布式学习框架,它通过中心服务器和边缘设备之间的迭代通信来训练全局模型。最近的研究表明,FL容易受到模型中毒攻击。已经提出了几种基于服务器的防御方法(例如,健壮聚合)来缓解此类攻击。然而,我们的经验表明,在极强的攻击下,这些防御方法无法保证FL的健壮性。更重要的是,我们观察到,只要全球模型受到污染,即使没有后续的攻击,攻击对全球模型的影响仍将在随后的几轮中存在。在这项工作中,我们提出了一种基于客户端的防御机制,称为联合学习白血球(FL-WBC),它可以缓解已经污染了全局模型的模型中毒攻击。FL-WBC的核心思想是在局部训练过程中识别对参数产生长期攻击作用的参数空间,并对该空间进行扰动。此外,在应用FL-WBC后,我们还得到了对模型中毒攻击的证明的健壮性保证和对FedAvg的收敛保证。我们在FasionMNIST和CIFAR10上进行了实验,以评估对最先进的模型中毒攻击的防御。实验结果表明,在IID和非IID设置下,该方法能够在5轮通信时间内有效缓解模型中毒攻击对全局模型的影响,且准确率几乎没有下降。我们的防御也是对现有基于服务器的健壮聚合方法的补充,可以进一步提高FL在极强攻击下的健壮性。
Federated learning (FL) is a popular distributed learning framework that trains a global model through iterative communications between a central server and edge devices. Recent works have demonstrated that FL is vulnerable to model poisoning attacks. Several server-based defense approaches (e.g. robust aggregation), have been proposed to mitigate such attacks. However, we empirically show that under extremely strong attacks, these defensive methods fail to guarantee the robustness of FL. More importantly, we observe that as long as the global model is polluted, the impact of attacks on the global model will remain in subsequent rounds even if there are no subsequent attacks. In this work, we propose a client-based defense, named White Blood Cell for Federated Learning (FL-WBC), which can mitigate model poisoning attacks that have already polluted the global model. The key idea of FL-WBC is to identify the parameter space where long-lasting attack effect on parameters resides and perturb that space during local training. Furthermore, we derive a certified robustness guarantee against model poisoning attacks and a convergence guarantee to FedAvg after applying our FL-WBC. We conduct experiments on FasionMNIST and CIFAR10 to evaluate the defense against state-of-the-art model poisoning attacks. The results demonstrate that our method can effectively mitigate model poisoning attack impact on the global model within 5 communication rounds with nearly no accuracy drop under both IID and Non-IID settings. Our defense is also complementary to existing server-based robust aggregation approaches and can further improve the robustness of FL under extremely strong attacks.