DPAD: Data Poisoning Attack Defense Mechanism for federated learning-based system

被引:0
作者
Basak, Santanu [1 ]
Chatterjee, Kakali [1 ]
机构
[1] Natl Inst Technol Patna, Dept Comp Sci & Engn, Patna 800005, Bihar, India
关键词
Data Poisoning Attack; Data Poisoning Attack Defense; Federated learning; Machine learning; Machine learning attack; Secure aggregation process;
D O I
10.1016/j.compeleceng.2024.109893
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
The Federated Learning (FL)-based approaches are increasing rapidly for different areas, such as home automation, smart healthcare, smart cars, etc. In FL, multiple users participate collaboratively and distributively to construct a global model without sharing raw data. The FL- based system resolves several issues of central server-based machine learning approaches, such as data availability, maintaining user privacy, etc. Still, some issues exist, such as data poisoning attacks and re-identification attacks. This paper proposes a Data Poisoning Attack Defense (DPAD) Mechanism that detects and defends against the data poisoning attack efficiently and secures the aggregation process for the Federated Learning-based systems. The DPAD verifies each client's updates using an audit mechanism that decides whether a local update is considered for aggregation. The experimental results show the effectiveness of the attack and the power of the DPAD mechanism compared with the state-of-the-art methods.
引用
收藏
页数:15
相关论文
共 42 条
  • [1] Alsuwat H, 2023, INT J ADV COMPUT SC, V14, P688
  • [2] Arpit D, 2017, A closer look at memorization in deep networks
  • [3] Balcan MF, 2012, Arxiv, DOI arXiv:1204.3514
  • [4] Bansal Yamini, 2021, ADV NEURAL INFORM PR
  • [5] DPPT : A differential privacy preservation technique for cyber-physical system
    Basak, Santanu
    Chatterjee, Kakali
    Singh, Ashish
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2023, 109
  • [6] Practical Secure Aggregation for Privacy-Preserving Machine Learning
    Bonawitz, Keith
    Ivanov, Vladimir
    Kreuter, Ben
    Marcedone, Antonio
    McMahan, H. Brendan
    Patel, Sarvar
    Ramage, Daniel
    Segal, Aaron
    Seth, Karn
    [J]. CCS'17: PROCEEDINGS OF THE 2017 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2017, : 1175 - 1191
  • [7] Understanding Distributed Poisoning Attack in Federated Learning
    Cao, Di
    Chang, Shan
    Lin, Zhijian
    Liu, Guohua
    Sunt, Donghong
    [J]. 2019 IEEE 25TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2019, : 233 - 239
  • [8] UNTRACEABLE ELECTRONIC MAIL, RETURN ADDRESSES, AND DIGITAL PSEUDONYMS
    CHAUM, DL
    [J]. COMMUNICATIONS OF THE ACM, 1981, 24 (02) : 84 - 88
  • [9] APFed: Anti-Poisoning Attacks in Privacy-Preserving Heterogeneous Federated Learning
    Chen, Xiao
    Yu, Haining
    Jia, Xiaohua
    Yu, Xiangzhan
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5749 - 5761
  • [10] Cheng KW, 2021, Arxiv, DOI [arXiv:1901.08755, DOI 10.48550/ARXIV.1901.08755]