Preserving Privacy and Security in Federated Learning

Preserving Privacy and Security in Federated Learning
复制标题

DOI:
10.1109/tnet.2023.3302016
复制
发表时间:
2022-02
期刊:
IEEE/ACM Transactions on Networking
影响因子:
--
通讯作者:
Truc D. T. Nguyen;M. Thai
Truc D. T. Nguyen;M. Thai
中科院分区:
其他
文献类型:
--
作者:
Truc D. T. Nguyen;M. Thai

文献摘要

相似文献

众所周知,联邦学习容易受到安全和隐私问题的影响。现有的研究要么集中在防止来自用户的中毒攻击,要么集中在隐藏来自服务器的本地模型更新,但不是两者兼而有之。然而,整合这两条研究路线仍然是一个关键的挑战,因为它们在威胁模型方面经常相互冲突。在这项工作中,我们开发了一个原则框架,既可以为用户提供隐私保证,又可以检测用户的中毒攻击。我们提出了一种新的威胁模型,该模型既包括诚实但好奇的服务器,也包括恶意用户,我们首先提出了一种使用同态加密的服务器安全聚合协议,以私有方式组合本地模型更新。然后,利用零知识证明协议将检测本地模型中的攻击的任务从服务器转移到用户。这里的关键观察是,服务器不再需要访问本地模型来进行攻击检测。因此,我们的框架使中央服务器能够在不违反安全聚合的隐私保证的情况下识别有毒的模型更新。
Federated learning is known to be vulnerable to both security and privacy issues. Existing research has focused either on preventing poisoning attacks from users or on concealing the local model updates from the server, but not both. However, integrating these two lines of research remains a crucial challenge since they often conflict with one another with respect to the threat model. In this work, we develop a principle framework that offers both privacy guarantees for users and detection against poisoning attacks from them. With a new threat model that includes both an honest-but-curious server and malicious users, we first propose a secure aggregation protocol using homomorphic encryption for the server to combine local model updates in a private manner. Then, a zero-knowledge proof protocol is leveraged to shift the task of detecting attacks in the local models from the server to the users. The key observation here is that the server no longer needs access to the local models for attack detection. Therefore, our framework enables the central server to identify poisoned model updates without violating the privacy guarantees of secure aggregation.