VPPFL: A verifiable privacy-preserving federated learning scheme against poisoning attacks

被引:4
|
作者
Huang, Yuxian [1 ]
Yang, Geng [1 ]
Zhou, Hao [1 ]
Dai, Hua [1 ]
Yuan, Dong [2 ]
Yu, Shui [3 ]
机构
[1] Nanjing Univ Posts & Telecommun, Sch Comp Sci & Technol, Nanjing 210003, Jiangsu, Peoples R China
[2] Univ Sydney, Sch Elect & Informat Engn, Sydney, NSW 2006, Australia
[3] Univ Technol Sydney, Sch Comp Sci, Sydney, NSW 2007, Australia
基金
中国国家自然科学基金;
关键词
Federated learning; Poisoning attacks; Differential privacy; Privacy-preserving; Defense strategy; SECURE;
D O I
10.1016/j.cose.2023.103562
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated Learning (FL) allows users to train a global model without sharing original data, enabling data to be available and invisible. However, not all users are benign and malicious users can corrupt the global model by uploading poisonous parameters. Compared with other machine learning schemes, two reasons make it easier for poisoning attacks to succeed in FL: 1) Malicious users can directly poison the parameters, which is more efficient than data poisoning; 2) Privacy preserving techniques, such as homomorphic encryption (HE) or differential privacy (DP), give poisonous parameters a cover, which makes it difficult for the server to detect outliers. To solve such a dilemma, in this paper, we propose VPPFL, a verifiable privacy-preserving federated learning scheme (VPPFL) with DP as the underlying technology. The VPPFL can defend against poisoning attacks and protect users' privacy with small computation and communication cost. Specifically, we design a verification mechanism, which can verify parameters that are perturbed by DP Noise, thus finding out poisonous parameters. In addition, we provide comprehensive analysis from the perspectives of security, convergence and complexity. Extensive experiments show that our scheme maintains the detection capability compared to prior works, but it only needs 15%-30% computation cost and 7%-14% communication cost.
引用
收藏
页数:13
相关论文
共 50 条
  • [41] A verifiable and privacy-preserving blockchain-based federated learning approach
    Irshad Ullah
    Xiaoheng Deng
    Xinjun Pei
    Ping Jiang
    Husnain Mushtaq
    Peer-to-Peer Networking and Applications, 2023, 16 : 2256 - 2270
  • [42] SVCA: Secure and Verifiable Chained Aggregation for Privacy-Preserving Federated Learning
    Xia, Yuanjun
    Liu, Yining
    Dong, Shi
    Li, Meng
    Guo, Cheng
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (10): : 18351 - 18365
  • [43] On the Security of Verifiable and Oblivious Secure Aggregation for Privacy-Preserving Federated Learning
    Wu, Jiahui
    Zhang, Weizhe
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 4324 - 4326
  • [44] PILE: Robust Privacy-Preserving Federated Learning Via Verifiable Perturbations
    Tang, Xiangyun
    Shen, Meng
    Li, Qi
    Zhu, Liehuang
    Xue, Tengfei
    Qu, Qiang
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (06) : 5005 - 5023
  • [45] A verifiable and privacy-preserving blockchain-based federated learning approach
    Ullah, Irshad
    Deng, Xiaoheng
    Pei, Xinjun
    Jiang, Ping
    Mushtaq, Husnain
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2023, 16 (05) : 2256 - 2270
  • [46] Federated learning scheme for privacy-preserving of medical data
    Bo W.
    Hongtao L.
    Jie W.
    Yina G.
    Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University, 2023, 50 (05): : 166 - 177
  • [47] BPFL: Blockchain-based privacy-preserving federated learning against poisoning attack
    Ren, Yanli
    Hu, Mingqi
    Yang, Zhe
    Feng, Guorui
    Zhang, Xinpeng
    INFORMATION SCIENCES, 2024, 665
  • [48] BPFL: Blockchain-based privacy-preserving federated learning against poisoning attack
    Ren, Yanli
    Hu, Mingqi
    Yang, Zhe
    Feng, Guorui
    Zhang, Xinpeng
    Information Sciences, 2024, 665
  • [49] RFed: Robustness-Enhanced Privacy-Preserving Federated Learning Against Poisoning Attack
    Miao, Yinbin
    Yan, Xinru
    Li, Xinghua
    Xu, Shujiang
    Liu, Ximeng
    Li, Hongwei
    Deng, Robert H.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 5814 - 5827
  • [50] More Efficient and Verifiable Privacy-Preserving Aggregation Scheme for Internet of Things-Based Federated Learning
    Shi, Rongquan
    Wei, Lifei
    Zhang, Lei
    APPLIED SCIENCES-BASEL, 2024, 14 (13):