Robust and Secure Federated Learning Against Hybrid Attacks: A Generic Architecture

被引:1
|
作者
Hao, Xiaohan [1 ]
Lin, Chao [2 ]
Dong, Wenhan [1 ]
Huang, Xinyi [1 ]
Xiong, Hui [1 ]
机构
[1] Hong Kong Univ Sci & Technol Guangzhou, Artificial Intelligence Thrust, Informat Hub, Guangzhou 511455, Peoples R China
[2] Fujian Normal Univ, Coll Comp & Cyber Secur, Fuzhou 350117, Peoples R China
基金
中国国家自然科学基金;
关键词
Federated learning; privacy protection; poisoning attacks; model inconsistency attacks; inference attacks; POISONING ATTACKS;
D O I
10.1109/TIFS.2023.3336521
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Federated Learning (FL) enables multiple clients to collaboratively train a model without sharing their private data. However, the deployment of FL in real-world applications is vulnerable to various attacks from both malicious servers and clients. While cryptographic methods are effective in resisting server-side attacks, they undermine the capability of client-side defenses that rely on plaintext updates. Several valuable defenses targeting hybrid attacks have been devised to address this challenge, concentrating on specific client-side threats. To improve scalability, we continue this research line to introduce a generic architecture covering more client-side attacks. In this paper, we propose a general architecture to enhance client-side defenses from plaintext to ciphertext domains. This architecture not only supports the server-side defenses, but also accommodates a broader range of client-side defenses, including Norm-based, Krum-based, and Cosine-based strategies. The core of our architecture is generic detection under ciphertext, which tackles the following conflict of integrating server-side and client-side defenses. That is, the former aims to protect parameters from exposure while the latter demands plaintext updates. We prove the security of our architecture through the Universal Composability framework. Additionally, we provide a comprehensive instantiation and extensive evaluations to demonstrate the effectiveness and robustness of our approach. Our experiments show that our architecture can maintain the effectiveness of current client-side defenses when parameters are encrypted, thus effectively resisting hybrid attacks.
引用
收藏
页码:1576 / 1588
页数:13
相关论文
共 50 条
  • [1] Efficient and Secure Federated Learning Against Backdoor Attacks
    Miao, Yinbin
    Xie, Rongpeng
    Li, Xinghua
    Liu, Zhiquan
    Choo, Kim-Kwang Raymond
    Deng, Robert H.
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (05) : 4619 - 4636
  • [2] FLCert: Provably Secure Federated Learning Against Poisoning Attacks
    Cao, Xiaoyu
    Zhang, Zaixi
    Jia, Jinyuan
    Gong, Neil Zhenqiang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 3691 - 3705
  • [3] Secure and verifiable federated learning against poisoning attacks in IoMT
    Niu, Shufen
    Zhou, Xusheng
    Wang, Ning
    Kong, Weiying
    Chen, Lihua
    COMPUTERS & ELECTRICAL ENGINEERING, 2025, 122
  • [4] CRFL: Certifiably Robust Federated Learning against Backdoor Attacks
    Xie, Chulin
    Chen, Minghao
    Chen, Pin-Yu
    Li, Bo
    INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 139, 2021, 139
  • [5] RoFL: A Robust Federated Learning Scheme Against Malicious Attacks
    Wei, Ming
    Liu, Xiaofan
    Ren, Wei
    WEB AND BIG DATA, PT III, APWEB-WAIM 2022, 2023, 13423 : 277 - 291
  • [6] Low dimensional secure federated learning framework against poisoning attacks
    Erdol, Eda Sena
    Ustubioglu, Beste
    Erdol, Hakan
    Ulutas, Guzin
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2024, 158 : 183 - 199
  • [7] Robust Secure Shield Architecture for Detection and Protection Against Invasive Attacks
    Lee, Young-woo
    Lim, Hyeonchan
    Lee, Youngkwang
    Kang, Sungho
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2020, 39 (10) : 3023 - 3034
  • [8] Robust Federated Learning: Maximum Correntropy Aggregation Against Byzantine Attacks
    Luan, Zhirong
    Li, Wenrui
    Liu, Meiqin
    Chen, Badong
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2025, 36 (01) : 62 - 75
  • [9] RoseAgg: Robust Defense Against Targeted Collusion Attacks in Federated Learning
    Yang, He
    Xi, Wei
    Shen, Yuhao
    Wu, Canhui
    Zhao, Jizhong
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 2951 - 2966
  • [10] An adaptive robust defending algorithm against backdoor attacks in federated learning
    Wang, Yongkang
    Zhai, Di-Hua
    He, Yongping
    Xia, Yuanqing
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 143 : 118 - 131