SRFL: A Secure & Robust Federated Learning framework for IoT with trusted execution environments

被引:14
作者
Cao, Yihao [1 ,2 ]
Zhang, Jianbiao [1 ,2 ]
Zhao, Yaru [1 ,2 ]
Su, Pengchong [3 ]
Huang, Haoxiang [1 ,2 ]
机构
[1] Beijing Univ Technol, Fac Informat Technol, Beijing 100124, Peoples R China
[2] Beijing Key Lab Trusted Comp, Beijing 100124, Peoples R China
[3] Peoples Publ Secur Univ China, Sch Informat & Cyber Secur, Beijing 100038, Peoples R China
关键词
Federated learning; Trusted execution environments; Robust aggregation; IoT; Privacy-preserving; ATTACKS;
D O I
10.1016/j.eswa.2023.122410
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning has gained popularity as it enables collaborative training without sharing local data. Despite its advantages, federated learning requires sharing the model parameters during model aggregation which poses security risks. In addition, existing secure federated learning frameworks cannot meet all the requirements of resource-constrained IoT devices and non-independent and identically distributed (non-IID) setting. This paper proposes a novel secure and robust federated learning framework (SRFL) with trusted execution environments (TEEs). The framework provides security and robustness for federated learning on IoT devices under non-IID data by leveraging TEEs to safeguard sensitive model components from being leaked. Simultaneously, we introduce a shared representation training approach to enhance the accuracy and security under non-IID setting. Furthermore, a multi-model robust aggregation method using membership degree is proposed to enhance robustness. This method uses membership degree generated by soft clustering to categorize clients for better aggregation performance. Additionally, we evaluate SRFL in a simulation environment, confirming that it improves accuracy by 5%-30% over FedAVG in non-IID setting and protects the model from membership inference attack and Byzantine attack. It also reduces backdoor attack success rate by 4%-10% more compared to other robust aggregation algorithms.
引用
收藏
页数:12
相关论文
共 42 条
[1]  
Bagdasaryan E, 2020, PR MACH LEARN RES, V108, P2938
[2]  
Blanchard P, 2017, ADV NEUR IN, V30
[3]  
Cao XY, 2022, Arxiv, DOI [arXiv:2012.13995, DOI 10.48550/ARXIV.2012.13995]
[4]  
Cohen G, 2017, IEEE IJCNN, P2921, DOI 10.1109/IJCNN.2017.7966217
[5]  
Collins L, 2021, PR MACH LEARN RES, V139
[6]   Security and Privacy-Enhanced Federated Learning for Anomaly Detection in IoT Infrastructures [J].
Cui, Lei ;
Qu, Youyang ;
Xie, Gang ;
Zeng, Deze ;
Li, Ruidong ;
Shen, Shigen ;
Yu, Shui .
IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (05) :3492-3500
[7]  
Denevi G, 2018, ADV NEUR IN, V31
[8]   Offloading Federated Learning Task to Edge Computing with Trust Execution Environment [J].
Dong, Shifu ;
Zeng, Deze ;
Gu, Lin ;
Guo, Song .
2020 IEEE 17TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2020), 2020, :491-496
[9]  
Fan Mo, 2021, MobiSys '21: Proceedings of the 19th Annual International Conference on Mobile Systems, Applications, and Services, P94, DOI 10.1145/3458864.3466628
[10]  
Fan Mo, 2020, MobiSys '20: Proceedings of the 18th International Conference on Mobile Systems, Applications, and Services, P161, DOI 10.1145/3386901.3388946