DefendFL: A Privacy-Preserving Federated Learning Scheme Against Poisoning Attacks

被引:0
|
作者
Liu, Jiao [1 ,2 ,3 ]
Li, Xinghua [1 ,2 ,3 ]
Liu, Ximeng [4 ]
Zhang, Haiyan [1 ,2 ,3 ,4 ]
Miao, Yinbin [1 ,2 ,3 ,4 ]
Deng, Robert H. [5 ]
机构
[1] Xidian Univ, State Key Lab Integrated Serv Networks, Xian 710126, Peoples R China
[2] Xidian Univ, Sch Cyber Engn, Xian 710071, Peoples R China
[3] AV Xian Aeronaut Comp Tech Res Inst, Xian 710068, Peoples R China
[4] Fuzhou Univ, Coll Comp & Data Sci, Fuzhou 350116, Peoples R China
[5] Singapore Management Univ, Sch Informat Syst, Singapore 178902, Singapore
基金
中国国家自然科学基金;
关键词
Federated learning (FL); poisoning attacks; poisoning detection; privacy protection; secure aggregation;
D O I
10.1109/TNNLS.2024.3423397
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning (FL) has become a popular mode of learning, allowing model training without the need to share data. Unfortunately, it remains vulnerable to privacy leakage and poisoning attacks, which compromise user data security and degrade model quality. Therefore, numerous privacy-preserving frameworks have been proposed, among which mask-based framework has certain advantages in terms of efficiency and functionality. However, it is more susceptible to poisoning attacks from malicious users, and current works lack practical means to detect such attacks within this framework. To overcome this challenge, we present DefendFL, an efficient, privacy-preserving, and poisoning-detectable mask-based FL scheme. We first leverage collinearity mask to protect users' gradient privacy. Then, cosine similarity is utilized to detect masked gradients to identify poisonous gradients. Meanwhile, a verification mechanism is designed to detect the mask, ensuring the mask's validity in aggregation and preventing poisoning attacks by intentionally changing the mask. Finally, we resist poisoning attacks by removing malicious gradients or lowering their weights in aggregation. Through security analysis and experimental evaluation, DefendFL can effectively detect and mitigate poisoning attacks while outperforming existing privacy-preserving detection works in efficiency.
引用
收藏
页数:14
相关论文
共 50 条
  • [41] A blockchain based privacy-preserving federated learning scheme for Internet of Vehicles
    Naiyu Wang
    Wenti Yang
    Xiaodong Wang
    Longfei Wu
    Zhitao Guan
    Xiaojiang Du
    Mohsen Guizani
    Digital Communications and Networks, 2024, 10 (01) : 126 - 134
  • [42] Privacy-Preserving Authenticated Federated Learning Scheme for Smart Healthcare System
    Tu, Jun
    Shen, Gang
    EMERGING INFORMATION SECURITY AND APPLICATIONS, EISA 2023, 2024, 2004 : 38 - 57
  • [43] A blockchain based privacy-preserving federated learning scheme for Internet of Vehicles
    Wang, Naiyu
    Yang, Wenti
    Wang, Xiaodong
    Wu, Longfei
    Guan, Zhitao
    Du, Xiaojiang
    Guizani, Mohsen
    DIGITAL COMMUNICATIONS AND NETWORKS, 2024, 10 (01) : 126 - 134
  • [44] A Privacy-Preserving Scheme for Multi-Party Vertical Federated Learning
    FAN Mochan
    ZHANG Zhipeng
    LI Difei
    ZHANG Qiming
    YAO Haidong
    ZTE Communications, 2024, 22 (04) : 89 - 96
  • [45] Anonymous and Efficient Authentication Scheme for Privacy-Preserving Federated Cross Learning
    Li, Zeshuai
    Liang, Xiaoyan
    ADVANCED INTELLIGENT COMPUTING TECHNOLOGY AND APPLICATIONS, PT IX, ICIC 2024, 2024, 14870 : 281 - 293
  • [46] Privacy-Preserving Federated Learning Against Label-Flipping Attacks on Non-IID Data
    Shen, Xicong
    Liu, Ying
    Li, Fu
    Li, Chunguang
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (01): : 1241 - 1255
  • [47] EPPDA: An Efficient Privacy-Preserving Data Aggregation Federated Learning Scheme
    Song, Jingcheng
    Wang, Weizheng
    Gadekallu, Thippa Reddy
    Cao, Jianyu
    Liu, Yining
    IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING, 2023, 10 (05): : 3047 - 3057
  • [48] Privacy-Preserving Data Aggregation Scheme Based on Federated Learning for IIoT
    Fan, Hongbin
    Zhou, Zhi
    MATHEMATICS, 2023, 11 (01)
  • [49] Split Aggregation: Lightweight Privacy-Preserving Federated Learning Resistant to Byzantine Attacks
    Lu, Zhi
    Lu, SongFeng
    Cui, YongQuan
    Tang, XueMing
    Wu, JunJun
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 5575 - 5590
  • [50] FedG2L: a privacy-preserving federated learning scheme base on "G2L" against poisoning attack
    Xu, Mengfan
    Li, Xinghua
    CONNECTION SCIENCE, 2023, 35 (01)