VPPFL: A verifiable privacy-preserving federated learning scheme against poisoning attacks

被引:4
|
作者
Huang, Yuxian [1 ]
Yang, Geng [1 ]
Zhou, Hao [1 ]
Dai, Hua [1 ]
Yuan, Dong [2 ]
Yu, Shui [3 ]
机构
[1] Nanjing Univ Posts & Telecommun, Sch Comp Sci & Technol, Nanjing 210003, Jiangsu, Peoples R China
[2] Univ Sydney, Sch Elect & Informat Engn, Sydney, NSW 2006, Australia
[3] Univ Technol Sydney, Sch Comp Sci, Sydney, NSW 2007, Australia
基金
中国国家自然科学基金;
关键词
Federated learning; Poisoning attacks; Differential privacy; Privacy-preserving; Defense strategy; SECURE;
D O I
10.1016/j.cose.2023.103562
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated Learning (FL) allows users to train a global model without sharing original data, enabling data to be available and invisible. However, not all users are benign and malicious users can corrupt the global model by uploading poisonous parameters. Compared with other machine learning schemes, two reasons make it easier for poisoning attacks to succeed in FL: 1) Malicious users can directly poison the parameters, which is more efficient than data poisoning; 2) Privacy preserving techniques, such as homomorphic encryption (HE) or differential privacy (DP), give poisonous parameters a cover, which makes it difficult for the server to detect outliers. To solve such a dilemma, in this paper, we propose VPPFL, a verifiable privacy-preserving federated learning scheme (VPPFL) with DP as the underlying technology. The VPPFL can defend against poisoning attacks and protect users' privacy with small computation and communication cost. Specifically, we design a verification mechanism, which can verify parameters that are perturbed by DP Noise, thus finding out poisonous parameters. In addition, we provide comprehensive analysis from the perspectives of security, convergence and complexity. Extensive experiments show that our scheme maintains the detection capability compared to prior works, but it only needs 15%-30% computation cost and 7%-14% communication cost.
引用
收藏
页数:13
相关论文
共 50 条
  • [21] SVeriFL: Successive verifiable federated learning with privacy-preserving
    Gao, Hang
    He, Ningxin
    Gao, Tiegang
    INFORMATION SCIENCES, 2023, 622 : 98 - 114
  • [22] A Verifiable and Privacy-Preserving Federated Learning Training Framework
    Duan, Haohua
    Peng, Zedong
    Xiang, Liyao
    Hu, Yuncong
    Li, Bo
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 5046 - 5058
  • [23] TPFL: Privacy-preserving personalized federated learning mitigates model poisoning attacks
    Zuo, Shaojun
    Xie, Yong
    Yao, Hehua
    Ke, Zhijie
    INFORMATION SCIENCES, 2025, 702
  • [24] APFed: Anti-Poisoning Attacks in Privacy-Preserving Heterogeneous Federated Learning
    Chen, Xiao
    Yu, Haining
    Jia, Xiaohua
    Yu, Xiangzhan
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5749 - 5761
  • [25] Efficient Privacy-Preserving Federated Learning Against Inference Attacks for IoT
    Miao, Yifeng
    Chen, Siguang
    2023 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE, WCNC, 2023,
  • [26] A Personalized Privacy-Preserving Scheme for Federated Learning
    Li, Zhenyu
    2022 IEEE INTERNATIONAL CONFERENCE ON ELECTRICAL ENGINEERING, BIG DATA AND ALGORITHMS (EEBDA), 2022, : 1352 - 1356
  • [27] Non-interactive verifiable privacy-preserving federated learning
    Xu, Yi
    Peng, Changgen
    Tan, Weijie
    Tian, Youliang
    Ma, Minyao
    Niu, Kun
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 128 : 365 - 380
  • [28] Privacy-Preserving and Verifiable Federated Learning Framework for Edge Computing
    Zhou, Hao
    Yang, Geng
    Huang, Yuxian
    Dai, Hua
    Xiang, Yang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 565 - 580
  • [29] Efficient Verifiable Protocol for Privacy-Preserving Aggregation in Federated Learning
    Eltaras, Tamer
    Sabry, Farida
    Labda, Wadha
    Alzoubi, Khawla
    Malluhi, Qutaibah
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 2977 - 2990
  • [30] ESVFL: Efficient and secure verifiable federated learning with privacy-preserving
    Cai, Jiewang
    Shen, Wenting
    Qin, Jing
    INFORMATION FUSION, 2024, 109