RobustFed: A Truth Inference Approach for Robust Federated Learning

RobustFed: A Truth Inference Approach for Robust Federated Learning
复制标题

DOI:
10.1145/3511808.3557439
复制
发表时间:
2021-07
期刊:
Proceedings of the 31st ACM International Conference on Information & Knowledge Management
影响因子:
--
通讯作者:
Farnaz Tahmasebian;Jian Lou;Li Xiong
Farnaz Tahmasebian;Jian Lou;Li Xiong
中科院分区:
其他
文献类型:
--
作者:
Farnaz Tahmasebian;Jian Lou;Li Xiong

文献摘要

相似文献

联合学习是一个重要的框架,使客户端(例如移动设备或组织)能够在中央服务器的编排下协作训练全局模型,同时保持本地数据的私密性。然而,联邦学习中的聚合步骤很容易受到对抗性攻击,因为中央服务器无法强制客户端的行为。因此,在此类攻击下,全局模型的性能和训练过程的收敛可能会受到影响。为了减轻这个漏洞,现有的工作提出了鲁棒的聚合方法,例如基于中值的聚合而不是平均。虽然它们确保了对拜占庭攻击的一定鲁棒性,但它们仍然容易受到标签翻转和高斯噪声攻击。在本文中,我们受到众包中真理推理方法的启发,通过将客户的可靠性纳入聚合中,提出了一种新颖的鲁棒聚合算法。我们使用各种机器学习模型在三个现实数据集上评估我们的解决方案。实验结果表明,我们的解决方案确保了强大的联邦学习,并且能够抵御各种类型的攻击,包括噪声数据攻击、拜占庭攻击和标签翻转攻击。
Federated learning is a prominent framework that enables clients (e.g., mobile devices or organizations) to collaboratively train a global model under a central server's orchestration while keeping local data private. However, the aggregation step in federated learning is vulnerable to adversarial attacks as the central server cannot enforce clients' behavior. As a result, the performance of the global model and convergence of the training process can be affected under such attacks. To mitigate this vulnerability, existing works have proposed robust aggregation methods such as median based aggregation instead of averaging. While they ensure some robustness against Byzantine attacks, they are still vulnerable to label flipping and Gaussian noise attacks. In this paper, we propose a novel robust aggregation algorithm inspired by the truth inference methods in crowdsourcing by incorporating the clients' reliability into aggregation. We evaluate our solution on three real-world datasets with a variety of machine learning models. Experimental results show that our solution ensures robust federated learning and is resilient to various types of attacks, including noisy data attacks, Byzantine attacks, and label flipping attacks.