Robust and Secure Federated Learning Against Hybrid Attacks: A Generic Architecture

被引:1
|
作者
Hao, Xiaohan [1 ]
Lin, Chao [2 ]
Dong, Wenhan [1 ]
Huang, Xinyi [1 ]
Xiong, Hui [1 ]
机构
[1] Hong Kong Univ Sci & Technol Guangzhou, Artificial Intelligence Thrust, Informat Hub, Guangzhou 511455, Peoples R China
[2] Fujian Normal Univ, Coll Comp & Cyber Secur, Fuzhou 350117, Peoples R China
基金
中国国家自然科学基金;
关键词
Federated learning; privacy protection; poisoning attacks; model inconsistency attacks; inference attacks; POISONING ATTACKS;
D O I
10.1109/TIFS.2023.3336521
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Federated Learning (FL) enables multiple clients to collaboratively train a model without sharing their private data. However, the deployment of FL in real-world applications is vulnerable to various attacks from both malicious servers and clients. While cryptographic methods are effective in resisting server-side attacks, they undermine the capability of client-side defenses that rely on plaintext updates. Several valuable defenses targeting hybrid attacks have been devised to address this challenge, concentrating on specific client-side threats. To improve scalability, we continue this research line to introduce a generic architecture covering more client-side attacks. In this paper, we propose a general architecture to enhance client-side defenses from plaintext to ciphertext domains. This architecture not only supports the server-side defenses, but also accommodates a broader range of client-side defenses, including Norm-based, Krum-based, and Cosine-based strategies. The core of our architecture is generic detection under ciphertext, which tackles the following conflict of integrating server-side and client-side defenses. That is, the former aims to protect parameters from exposure while the latter demands plaintext updates. We prove the security of our architecture through the Universal Composability framework. Additionally, we provide a comprehensive instantiation and extensive evaluations to demonstrate the effectiveness and robustness of our approach. Our experiments show that our architecture can maintain the effectiveness of current client-side defenses when parameters are encrypted, thus effectively resisting hybrid attacks.
引用
收藏
页码:1576 / 1588
页数:13
相关论文
共 50 条
  • [41] Defending Against Poisoning Attacks in Federated Learning with Blockchain
    Dong N.
    Wang Z.
    Sun J.
    Kampffmeyer M.
    Knottenbelt W.
    Xing E.
    IEEE Transactions on Artificial Intelligence, 2024, 5 (07): : 1 - 13
  • [42] Data Poisoning Attacks Against Federated Learning Systems
    Tolpegin, Vale
    Truex, Stacey
    Gursoy, Mehmet Emre
    Liu, Ling
    COMPUTER SECURITY - ESORICS 2020, PT I, 2020, 12308 : 480 - 501
  • [43] Attacks against Federated Learning Defense Systems and their Mitigation
    Lewis, Cody
    Varadharajan, Vijay
    Noman, Nasimul
    JOURNAL OF MACHINE LEARNING RESEARCH, 2023, 24
  • [44] MATFL: Defending Against Synergetic Attacks in Federated Learning
    Yang, Wen
    Peng, Luyao
    Tang, Xiangyun
    Weng, Yu
    Proceedings - IEEE Congress on Cybermatics: 2023 IEEE International Conferences on Internet of Things, iThings 2023, IEEE Green Computing and Communications, GreenCom 2023, IEEE Cyber, Physical and Social Computing, CPSCom 2023 and IEEE Smart Data, SmartData 2023, 2023, : 313 - 319
  • [45] CONTRA: Defending Against Poisoning Attacks in Federated Learning
    Awan, Sana
    Luo, Bo
    Li, Fengjun
    COMPUTER SECURITY - ESORICS 2021, PT I, 2021, 12972 : 455 - 475
  • [46] DEFEAT: A decentralized federated learning against gradient attacks
    Lu, Guangxi
    Xiong, Zuobin
    Li, Ruinian
    Mohammad, Nael
    Li, Yingshu
    Li, Wei
    HIGH-CONFIDENCE COMPUTING, 2023, 3 (03):
  • [47] Defending Against Targeted Poisoning Attacks in Federated Learning
    Erbil, Pinar
    Gursoy, M. Emre
    2022 IEEE 4TH INTERNATIONAL CONFERENCE ON TRUST, PRIVACY AND SECURITY IN INTELLIGENT SYSTEMS, AND APPLICATIONS, TPS-ISA, 2022, : 198 - 207
  • [48] Defending Against Byzantine Attacks in Quantum Federated Learning
    Xia, Qi
    Tao, Zeyi
    Li, Qun
    2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, : 145 - 152
  • [49] A Selective Defense Strategy for Federated Learning Against Attacks
    Chen Z.
    Jiang H.
    Zhou Y.
    Dianzi Yu Xinxi Xuebao/Journal of Electronics and Information Technology, 2024, 46 (03): : 1119 - 1127
  • [50] Provably Secure Federated Learning against Malicious Clients
    Cao, Xiaoyu
    Jia, Jinyuan
    Gong, Neil Zhenqiang
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 6885 - 6893