Provably Secure Federated Learning against Malicious Clients

Provably Secure Federated Learning against Malicious Clients
复制标题

DOI:
10.1609/aaai.v35i8.16849
复制
发表时间:
2021-02
期刊:
ArXiv
影响因子:
--
通讯作者:
Xiaoyu Cao;Jinyuan Jia;N. Gong
Xiaoyu Cao;Jinyuan Jia;N. Gong
中科院分区:
其他
文献类型:
--
作者:
Xiaoyu Cao;Jinyuan Jia;N. Gong

文献摘要

被引文献

相似文献

联邦学习使客户能够协作学习共享的全局模型,而无需与云服务器共享本地训练数据。然而,恶意客户端可以破坏全局模型来预测测试示例的错误标签。针对恶意客户端的现有防御利用拜占庭健壮的联邦学习方法。然而,这些方法不能证明地保证测试示例的预测标签不受恶意客户机的影响。我们通过集成联合学习来弥补这一差距。特别是,给定任何基础联邦学习算法,我们使用该算法来学习多个全局模型,每个模型都是使用随机选择的客户机子集来学习的。在预测测试样例的标签时,我们在全局模型中采取多数投票。我们证明了使用任何基本联邦学习算法的集成联邦学习对于恶意客户端是安全的。具体来说,我们的集成全局模型为测试示例预测的标签可证明不受有限数量的恶意客户端的影响。此外,我们还证明了所导出的界是紧的。我们在MNIST和人类活动识别数据集上评估了我们的方法。例如,当1000个客户端中有20个是恶意客户端时,我们的方法可以在MNIST上实现88%的认证准确率。
Federated learning enables clients to collaboratively learn a shared global model without sharing their local training data with a cloud server. However, malicious clients can corrupt the global model to predict incorrect labels for testing examples. Existing defenses against malicious clients leverage Byzantine-robust federated learning methods. However, these methods cannot provably guarantee that the predicted label for a testing example is not affected by malicious clients. We bridge this gap via ensemble federated learning. In particular, given any base federated learning algorithm, we use the algorithm to learn multiple global models, each of which is learnt using a randomly selected subset of clients. When predicting the label of a testing example, we take majority vote among the global models. We show that our ensemble federated learning with any base federated learning algorithm is provably secure against malicious clients. Specifically, the label predicted by our ensemble global model for a testing example is provably not affected by a bounded number of malicious clients. Moreover, we show that our derived bound is tight. We evaluate our method on MNIST and Human Activity Recognition datasets. For instance, our method can achieve a certified accuracy of 88% on MNIST when 20 out of 1,000 clients are malicious.