Privacy-preserving and Byzantine-robust Federated Learning Framework using Permissioned Blockchain

被引:13
作者
Kasyap, Harsh [1 ]
Tripathy, Somanath [1 ]
机构
[1] Indian Inst Technol Patna, Dept Comp Sci & Engn, Patna, India
关键词
Federated learning; Poisoning attack; Robustness; Inference attack; Privacy; Permissioned blockchain; ATTACKS;
D O I
10.1016/j.eswa.2023.122210
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Data is readily available with the growing number of smart and IoT devices. However, application-specific data is available in small chunks and distributed across demographics. Also, sharing data online brings serious concerns and poses various security and privacy threats. To solve these issues, federated learning (FL) has emerged as a promising secure and collaborative learning solution. FL brings the machine learning model to the data owners, trains locally, and then sends the trained model to the central curator for final aggregation. However, FL is prone to poisoning and inference attacks in the presence of malicious participants and curious servers. Different Byzantine-robust aggregation schemes exist to mitigate poisoning attacks, but they require raw access to the model updates. Thus, it exposes the submitted updates to inference attacks. This work proposes a Byzantine-Robust and Inference-Resistant Federated Learning Framework using Permissioned Blockchain, called PrivateFL. PrivateFL replaces the central curator with the Hyperledger Fabric network. Further, we propose VPSA (Vertically Partitioned Secure Aggregation), tailored to PrivateFL framework, which performs robust and secure aggregation. Theoretical analysis proves that VPSA resists inference attacks, even if n-1 peers are compromised. A secure prediction mechanism to securely query a global model is also proposed for PrivateFL framework. Experimental evaluation shows that PrivateFL performs better than the traditional (centralized) learning systems, while being resistant to poisoning and inference attacks.
引用
收藏
页数:11
相关论文
共 40 条
  • [1] Hyperledger Fabric: A Distributed Operating System for Permissioned Blockchains
    Androulaki, Elli
    Barger, Artem
    Bortnikov, Vita
    Cachin, Christian
    Christidis, Konstantinos
    De Caro, Angelo
    Enyeart, David
    Ferris, Christopher
    Laventman, Gennady
    Manevich, Yacov
    Muralidharan, Srinivasan
    Murthy, Chet
    Binh Nguyen
    Sethi, Manish
    Singh, Gari
    Smith, Keith
    Sorniotti, Alessandro
    Stathakopoulou, Chrysoula
    Vukolic, Marko
    Cocco, Sharon Weed
    Yellick, Jason
    [J]. EUROSYS '18: PROCEEDINGS OF THE THIRTEENTH EUROSYS CONFERENCE, 2018,
  • [2] Bagdasaryan E, 2020, PR MACH LEARN RES, V108, P2938
  • [3] Blanchard P, 2017, ADV NEUR IN, V30
  • [4] Understanding Distributed Poisoning Attack in Federated Learning
    Cao, Di
    Chang, Shan
    Lin, Zhijian
    Liu, Guohua
    Sunt, Donghong
    [J]. 2019 IEEE 25TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED SYSTEMS (ICPADS), 2019, : 233 - 239
  • [5] FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping
    Cao, Xiaoyu
    Fang, Minghong
    Liu, Jia
    Gong, Neil Zhenqiang
    [J]. 28TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2021), 2021,
  • [6] European Commission, 2016, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation)
  • [7] Fang MH, 2020, PROCEEDINGS OF THE 29TH USENIX SECURITY SYMPOSIUM, P1623
  • [8] Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures
    Fredrikson, Matt
    Jha, Somesh
    Ristenpart, Thomas
    [J]. CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2015, : 1322 - 1333
  • [9] Efficient and Privacy-Enhanced Federated Learning for Industrial Artificial Intelligence
    Hao, Meng
    Li, Hongwei
    Luo, Xizhao
    Xu, Guowen
    Yang, Haomiao
    Liu, Sen
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2020, 16 (10) : 6532 - 6542
  • [10] Hayes J, 2018, ADV NEUR IN, V31