DBFL: Dynamic Byzantine-Robust Privacy Preserving Federated Learning in Heterogeneous Data Scenario

被引:0
|
作者
Chen, Xiaoli [1 ]
Tian, Youliang [1 ,2 ]
Wang, Shuai [1 ]
Yang, Kedi [1 ]
Zhao, Wei [3 ]
Xiong, Jinbo [4 ]
机构
[1] Guizhou Univ, Coll Comp Sci & Technol, Guizhou Prov Key Lab Cryptog & Blockchain Technol, Guiyang 550025, Guizhou, Peoples R China
[2] Guizhou Univ, Coll Big Data & Informat Engn, Guiyang 550025, Guizhou, Peoples R China
[3] Guizhou Univ, Coll Math & Stat, Guiyang 550025, Guizhou, Peoples R China
[4] Fujian Normal Univ, Coll Comp & Cyber Secur, Fujian Prov Key Lab Network Secur & Cryptol, Fuzhou 350117, Fujian, Peoples R China
基金
中国国家自然科学基金;
关键词
Defense strategy; Poisoning attacks; Privacy protection; Homomorphic encryption; Federated learning;
D O I
10.1016/j.ins.2024.121849
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Privacy Preserving Federated Learning (PPFL) protects the clients' local data privacy uploading encrypted gradients to the server. However, in real-world scenarios, the heterogeneous distribution of client data makes it challenging to identify poisoning gradients. During local iterations, the models continuously move in different directions, which causes the boundary between benign and malicious gradients to persistently shift. To address these challenges, we design a Dynamic Byzantine-robust Federated Learning (DBFL) defense strategy based on Two trapdoor Homomorphic Encryption (THE), which enables the detection of encrypted poisoning attacks in heterogeneous data scenarios. Specifically, we introduce a secure Manhattan distance method that accurately measures the differences between elements in two encrypted gradients, allowing for precise detection of poisoning attacks in heterogeneous data scenarios while maintaining privacy. Furthermore, we design a Byzantine-tolerant aggregation mechanism based on dynamic threshold, where the threshold is capable of adapting to the continuously changing boundary between poisoning gradients and benign gradients in heterogeneous data scenarios. This ensures DBFL to effectively exclude poisoning gradients even when 70% of the clients are malicious and controlled by Byzantine attackers. Security analysis demonstrates that DBFL achieves IND-CPA security. Extensive evaluations on two benchmark datasets (i.e., MNIST and CIFAR-10) show that DBFL outperforms existing defense strategies. In particular, DBFL achieves 7%-40% accuracy improvement in the non-IID setting compared to existing solutions for defending against untargeted and targeted attacks.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Privacy-preserving Byzantine-robust federated learning
    Ma, Xu
    Zhou, Yuqing
    Wang, Laihua
    Miao, Meixia
    COMPUTER STANDARDS & INTERFACES, 2022, 80
  • [2] Privacy-Preserving and Byzantine-Robust Federated Learning
    Dong, Caiqin
    Weng, Jian
    Li, Ming
    Liu, Jia-Nan
    Liu, Zhiquan
    Cheng, Yudan
    Yu, Shui
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (02) : 889 - 904
  • [3] Efficient and Privacy-Preserving Byzantine-robust Federated Learning
    Luan, Shijie
    Lu, Xiang
    Zhang, Zhuangzhuang
    Chang, Guangsheng
    Guo, Yunchuan
    IEEE CONFERENCE ON GLOBAL COMMUNICATIONS, GLOBECOM, 2023, : 2202 - 2208
  • [4] Lightweight Byzantine-Robust and Privacy-Preserving Federated Learning
    Lu, Zhi
    Lu, Songfeng
    Cui, Yongquan
    Wu, Junjun
    Nie, Hewang
    Xiao, Jue
    Yi, Zepu
    EURO-PAR 2024: PARALLEL PROCESSING, PART II, EURO-PAR 2024, 2024, 14802 : 274 - 287
  • [5] Byzantine-Robust and Privacy-Preserving Federated Learning With Irregular Participants
    Chen, Yinuo
    Tan, Wuzheng
    Zhong, Yijian
    Kang, Yulin
    Yang, Anjia
    Weng, Jian
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (21): : 35193 - 35205
  • [6] Efficient Byzantine-Robust and Privacy-Preserving Federated Learning on Compressive Domain
    Hu, Guiqiang
    Li, Hongwei
    Fan, Wenshu
    Zhang, Yushu
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (04): : 7116 - 7127
  • [7] Privacy-Preserving Byzantine-Robust Federated Learning via Blockchain Systems
    Miao, Yinbin
    Liu, Ziteng
    Li, Hongwei
    Choo, Kim-Kwang Raymond
    Deng, Robert H.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 2848 - 2861
  • [8] Privacy-Preserving Byzantine-Robust Federated Learning via Blockchain Systems
    Miao, Yinbin
    Liu, Ziteng
    Li, Hongwei
    Choo, Kim-Kwang Raymond
    Deng, Robert H.
    IEEE Transactions on Information Forensics and Security, 2022, 17 : 2848 - 2861
  • [9] FedCCW: a privacy-preserving Byzantine-robust federated learning with local differential privacy for healthcare
    Lianfu Zhang
    Guangwei Fang
    Zuowen Tan
    Cluster Computing, 2025, 28 (3)
  • [10] PPBR-FL: A Privacy-Preserving and Byzantine-Robust Federated Learning System
    Lin, Ying
    Ning, Shengfu
    Hu, Jianpeng
    Liu, Jiansong
    Cao, Yifan
    Zhang, Junyuan
    Pi, Huan
    KNOWLEDGE SCIENCE, ENGINEERING AND MANAGEMENT, KSEM 2022, PT III, 2022, 13370 : 39 - 50