FLCert: Provably Secure Federated Learning Against Poisoning Attacks

FLCert: Provably Secure Federated Learning Against Poisoning Attacks
复制标题

DOI:
10.1109/tifs.2022.3212174
复制
发表时间:
2022-10
影响因子:
6.8
通讯作者:
Xiaoyu Cao;Zaixi Zhang;Jinyuan Jia;N. Gong
Xiaoyu Cao;Zaixi Zhang;Jinyuan Jia;N. Gong
中科院分区:
计算机科学1区
文献类型:
--
作者:
Xiaoyu Cao;Zaixi Zhang;Jinyuan Jia;N. Gong

文献摘要

被引文献

相似文献

由于其分布式性质,联邦学习容易受到中毒攻击,其中恶意客户端通过操纵发送到云服务器的本地训练数据和/或本地模型更新来毒害训练过程,使得中毒的全局模型错误地分类许多不加区分的测试输入或攻击者选择的输入。现有的防御主要利用Byzantine-robust联邦学习方法或检测恶意客户端。然而,这些防御不具有针对中毒攻击的可证明的安全保证,并且可能容易受到更高级的攻击。在这项工作中,我们的目标是弥合差距,提出FLCert,集成联邦学习框架,这是可证明安全的中毒攻击与有限数量的恶意客户端。我们的核心思想是将客户端分成组,使用任何现有的联邦学习方法为每组客户端学习一个全局模型,并在全局模型中进行多数投票来对测试输入进行分类。具体来说,我们考虑了两种方法来对客户端进行分组,并相应地提出了FLCert的两种变体,即,FLCert-P在每个组中随机抽样客户端,FLCert-D确定性地将客户端划分到不相交的组。我们在多个数据集上进行的大量实验表明,我们的FLCert为测试输入预测的标签可证明不受有限数量的恶意客户端的影响,无论他们使用什么中毒攻击。
Due to its distributed nature, federated learning is vulnerable to poisoning attacks, in which malicious clients poison the training process via manipulating their local training data and/or local model updates sent to the cloud server, such that the poisoned global model misclassifies many indiscriminate test inputs or attacker-chosen ones. Existing defenses mainly leverage Byzantine-robust federated learning methods or detect malicious clients. However, these defenses do not have provable security guarantees against poisoning attacks and may be vulnerable to more advanced attacks. In this work, we aim to bridge the gap by proposing FLCert, an ensemble federated learning framework, that is provably secure against poisoning attacks with a bounded number of malicious clients. Our key idea is to divide the clients into groups, learn a global model for each group of clients using any existing federated learning method, and take a majority vote among the global models to classify a test input. Specifically, we consider two methods to group the clients and propose two variants of FLCert correspondingly, i.e., FLCert-P that randomly samples clients in each group, and FLCert-D that divides clients to disjoint groups deterministically. Our extensive experiments on multiple datasets show that the label predicted by our FLCert for a test input is provably unaffected by a bounded number of malicious clients, no matter what poisoning attacks they use.