DefendFL: A Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks

被引:0
|
作者
Liu, Jiao [1 ,2 ,3 ]
Li, Xinghua [1 ,2 ,3 ]
Liu, Ximeng [4 ]
Zhang, Haiyan [1 ,2 ,3 ,4 ]
Miao, Yinbin [1 ,2 ,3 ,4 ]
Deng, Robert H. [5 ]
机构
[1] Xidian Univ, State Key Lab Integrated Serv Networks, Xian 710126, Peoples R China
[2] Xidian Univ, Sch Cyber Engn, Xian 710071, Peoples R China
[3] AV Xian Aeronaut Comp Tech Res Inst, Xian 710068, Peoples R China
[4] Fuzhou Univ, Coll Comp & Data Sci, Fuzhou 350116, Peoples R China
[5] Singapore Management Univ, Sch Informat Syst, Singapore 178902, Singapore
基金
中国国家自然科学基金;
关键词
Federated learning (FL); poisoning attacks; poisoning detection; privacy protection; secure aggregation;
D O I
10.1109/TNNLS.2024.3423397
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning (FL) has become a popular mode of learning, allowing model training without the need to share data. Unfortunately, it remains vulnerable to privacy leakage and poisoning attacks, which compromise user data security and degrade model quality. Therefore, numerous privacy-preserving frameworks have been proposed, among which mask-based framework has certain advantages in terms of efficiency and functionality. However, it is more susceptible to poisoning attacks from malicious users, and current works lack practical means to detect such attacks within this framework. To overcome this challenge, we present DefendFL, an efficient, privacy-preserving, and poisoning-detectable mask-based FL scheme. We first leverage collinearity mask to protect users' gradient privacy. Then, cosine similarity is utilized to detect masked gradients to identify poisonous gradients. Meanwhile, a verification mechanism is designed to detect the mask, ensuring the mask's validity in aggregation and preventing poisoning attacks by intentionally changing the mask. Finally, we resist poisoning attacks by removing malicious gradients or lowering their weights in aggregation. Through security analysis and experimental evaluation, DefendFL can effectively detect and mitigate poisoning attacks while outperforming existing privacy-preserving detection works in efficiency.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] A Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks in Smart Grid
    Li, Xiumin
    Wen, Mi
    He, Siying
    Lu, Rongxing
    Wang, Liangliang
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (09): : 16805 - 16816
  • [2] VPPFL: A verifiable privacy-preserving federated learning scheme against poisoning attacks
    Huang, Yuxian
    Yang, Geng
    Zhou, Hao
    Dai, Hua
    Yuan, Dong
    Yu, Shui
    COMPUTERS & SECURITY, 2024, 136
  • [3] A survey on privacy-preserving federated learning against poisoning attacks
    Xia, Feng
    Cheng, Wenhao
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (10): : 13565 - 13582
  • [4] Privacy-Preserving Detection of Poisoning Attacks in Federated Learning
    Muhr, Trent
    Zhang, Wensheng
    2022 19TH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY & TRUST (PST), 2022,
  • [5] A Robust Privacy-Preserving Federated Learning Model Against Model Poisoning Attacks
    Yazdinejad, Abbas
    Dehghantanha, Ali
    Karimipour, Hadis
    Srivastava, Gautam
    Parizi, Reza M.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 6693 - 6708
  • [6] Robust and privacy-preserving federated learning with distributed additive encryption against poisoning attacks
    Zhang, Fan
    Huang, Hui
    Chen, Zhixiong
    Huang, Zhenjie
    COMPUTER NETWORKS, 2024, 245
  • [7] ShieldFL: Mitigating Model Poisoning Attacks in Privacy-Preserving Federated Learning
    Ma, Zhuoran
    Ma, Jianfeng
    Miao, Yinbin
    Li, Yingjiu
    Deng, Robert H.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 1639 - 1654
  • [8] Efficient and Privacy-Preserving Federated Learning against Poisoning Adversaries
    Zhao J.
    Zhu H.
    Wang F.
    Zheng Y.
    Lu R.
    Li H.
    IEEE Transactions on Services Computing, 2024, 17 (05): : 1 - 14
  • [9] PPFL-IDS: Privacy-Preserving Federated Learning Based IDS Against Poisoning Attacks
    Xu, Mengfan
    Li, Xinghua
    MOBILE NETWORKS & APPLICATIONS, 2023,
  • [10] TPFL: Privacy-preserving personalized federated learning mitigates model poisoning attacks
    Zuo, Shaojun
    Xie, Yong
    Yao, Hehua
    Ke, Zhijie
    Information Sciences, 2025, 702