VPPFL: A verifiable privacy-preserving federated learning scheme against poisoning attacks

被引:4
|
作者
Huang, Yuxian [1 ]
Yang, Geng [1 ]
Zhou, Hao [1 ]
Dai, Hua [1 ]
Yuan, Dong [2 ]
Yu, Shui [3 ]
机构
[1] Nanjing Univ Posts & Telecommun, Sch Comp Sci & Technol, Nanjing 210003, Jiangsu, Peoples R China
[2] Univ Sydney, Sch Elect & Informat Engn, Sydney, NSW 2006, Australia
[3] Univ Technol Sydney, Sch Comp Sci, Sydney, NSW 2007, Australia
基金
中国国家自然科学基金;
关键词
Federated learning; Poisoning attacks; Differential privacy; Privacy-preserving; Defense strategy; SECURE;
D O I
10.1016/j.cose.2023.103562
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated Learning (FL) allows users to train a global model without sharing original data, enabling data to be available and invisible. However, not all users are benign and malicious users can corrupt the global model by uploading poisonous parameters. Compared with other machine learning schemes, two reasons make it easier for poisoning attacks to succeed in FL: 1) Malicious users can directly poison the parameters, which is more efficient than data poisoning; 2) Privacy preserving techniques, such as homomorphic encryption (HE) or differential privacy (DP), give poisonous parameters a cover, which makes it difficult for the server to detect outliers. To solve such a dilemma, in this paper, we propose VPPFL, a verifiable privacy-preserving federated learning scheme (VPPFL) with DP as the underlying technology. The VPPFL can defend against poisoning attacks and protect users' privacy with small computation and communication cost. Specifically, we design a verification mechanism, which can verify parameters that are perturbed by DP Noise, thus finding out poisonous parameters. In addition, we provide comprehensive analysis from the perspectives of security, convergence and complexity. Extensive experiments show that our scheme maintains the detection capability compared to prior works, but it only needs 15%-30% computation cost and 7%-14% communication cost.
引用
收藏
页数:13
相关论文
共 50 条
  • [31] A privacy-preserving and verifiable federated learning method based on blockchain
    Fang, Chen
    Guo, Yuanbo
    Ma, Jiali
    Xie, Haodong
    Wang, Yifeng
    COMPUTER COMMUNICATIONS, 2022, 186 : 1 - 11
  • [32] Verifiable Privacy-Preserving Scheme Based on Vertical Federated Random Forest
    Hou, Jinpeng
    Su, Mang
    Fu, Anmin
    Yu, Yan
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (22) : 22158 - 22172
  • [33] Privacy-Preserving Federated Learning Resistant to Byzantine Attacks
    Mu X.-T.
    Cheng K.
    Song A.-X.
    Zhang T.
    Zhang Z.-W.
    Shen Y.-L.
    Jisuanji Xuebao/Chinese Journal of Computers, 2024, 47 (04): : 842 - 861
  • [34] Cross the Chasm: Scalable Privacy-Preserving Federated Learning against Poisoning Attack
    Li, Yiran
    Hu, Guiqiang
    Liu, Xiaoyuan
    Ying, Zuobin
    2021 18TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2021,
  • [35] Shield Against Gradient Leakage Attacks: Adaptive Privacy-Preserving Federated Learning
    Hu, Jiahui
    Wang, Zhibo
    Shen, Yongsheng
    Lin, Bohan
    Sun, Peng
    Pang, Xiaoyi
    Liu, Jian
    Ren, Kui
    IEEE-ACM TRANSACTIONS ON NETWORKING, 2024, 32 (02) : 1407 - 1422
  • [36] Secure and verifiable federated learning against poisoning attacks in IoMT
    Niu, Shufen
    Zhou, Xusheng
    Wang, Ning
    Kong, Weiying
    Chen, Lihua
    COMPUTERS & ELECTRICAL ENGINEERING, 2025, 122
  • [37] VOSA: Verifiable and Oblivious Secure Aggregation for Privacy-Preserving Federated Learning
    Wang, Yong
    Zhang, Aiqing
    Wu, Shu
    Yu, Shui
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (05) : 3601 - 3616
  • [38] Verifiable Federated Learning With Privacy-Preserving Data Aggregation for Consumer Electronics
    Xie, Haoran
    Wang, Yujue
    Ding, Yong
    Yang, Changsong
    Zheng, Haibin
    Qin, Bo
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2024, 70 (01) : 2696 - 2707
  • [39] Verifiable Privacy-Preserving Federated Learning Under Multiple Encrypted Keys
    Shen, Xiaoying
    Luo, Xue
    Yuan, Feng
    Wang, Baocang
    Chen, Yange
    Tang, Dianhua
    Gao, Le
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (02) : 3430 - 3445
  • [40] Communication-Efficient and Privacy-Preserving Verifiable Aggregation for Federated Learning
    Peng, Kaixin
    Shen, Xiaoying
    Gao, Le
    Wang, Baocang
    Lu, Yichao
    ENTROPY, 2023, 25 (08)