Provably Secure Federated Learning against Malicious Clients

被引:0
|
作者
Cao, Xiaoyu [1 ]
Jia, Jinyuan [1 ]
Gong, Neil Zhenqiang [1 ]
机构
[1] Duke Univ, Durham, NC 27708 USA
来源
THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE | 2021年 / 35卷
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning enables clients to collaboratively learn a shared global model without sharing their local training data with a cloud server. However, malicious clients can corrupt the global model to predict incorrect labels for testing examples. Existing defenses against malicious clients leverage Byzantine-robust federated learning methods. However, these methods cannot provably guarantee that the predicted label for a testing example is not affected by malicious clients. We bridge this gap via ensemble federated learning. In particular, given any base federated learning algorithm, we use the algorithm to learn multiple global models, each of which is learnt using a randomly selected subset of clients. When predicting the label of a testing example, we take majority vote among the global models. We show that our ensemble federated learning with any base federated learning algorithm is provably secure against malicious clients. Specifically, the label predicted by our ensemble global model for a testing example is provably not affected by a bounded number of malicious clients. Moreover, we show that our derived bound is tight. We evaluate our method on MNIST and Human Activity Recognition datasets. For instance, our method can achieve a certified accuracy of 88% on MNIST when 20 out of 1,000 clients are malicious.
引用
收藏
页码:6885 / 6893
页数:9
相关论文
共 50 条
  • [1] Federated learning secure model: A framework for malicious clients detection
    Kolasa, Dominik
    Pilch, Kinga
    Mazurczyk, Wojciech
    SOFTWAREX, 2024, 27
  • [2] FedGT: Identification of Malicious Clients in Federated Learning With Secure Aggregation
    Xhemrishi, Marvin
    Oestman, Johan
    Wachter-Zeh, Antonia
    Graell i Amat, Alexandre
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 2577 - 2592
  • [3] FLCert: Provably Secure Federated Learning Against Poisoning Attacks
    Cao, Xiaoyu
    Zhang, Zaixi
    Jia, Jinyuan
    Gong, Neil Zhenqiang
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 3691 - 3705
  • [4] FLUK: Protecting Federated Learning Against Malicious Clients for Internet of Vehicles
    Zhu, Mengde
    Ning, Wanyi
    Qi, Qi
    Wang, Jingyu
    Zhuang, Zirui
    Sun, Haifeng
    Huang, Jun
    Liao, Jianxin
    EURO-PAR 2024: PARALLEL PROCESSING, PART II, EURO-PAR 2024, 2024, 14802 : 454 - 469
  • [5] Fault Tolerant and Malicious Secure Federated Learning
    Karakoc, Ferhat
    Kupcu, Alptekin
    Onen, Melek
    CRYPTOLOGY AND NETWORK SECURITY, PT II, CANS 2024, 2025, 14906 : 73 - 95
  • [6] FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious Clients
    Zhang, Zaixi
    Cao, Xiaoyu
    Jia, Jinyuan
    Gong, Neil Zhenqiang
    PROCEEDINGS OF THE 28TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2022, 2022, : 2545 - 2555
  • [7] Fake or Compromised? Making Sense of Malicious Clients in Federated Learning
    Mozaffari, Hamid
    Choudhary, Sunav
    Houmansadr, Amir
    COMPUTER SECURITY-ESORICS 2024, PT I, 2024, 14982 : 187 - 207
  • [8] ELSA: Secure Aggregation for Federated Learning with Malicious Actors
    Rathee, Mayank
    Shen, Conghao
    Wagh, Sameer
    Popa, Raluca Ada
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 1961 - 1979
  • [9] A Flexible and Scalable Malicious Secure Aggregation Protocol for Federated Learning
    Tang, Jinling
    Xu, Haixia
    Wang, Mingsheng
    Tang, Tao
    Peng, Chunying
    Liao, Huimei
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 4174 - 4187
  • [10] FedDMC: Efficient and Robust Federated Learning via Detecting Malicious Clients
    Mu, Xutong
    Cheng, Ke
    Shen, Yulong
    Li, Xiaoxiao
    Chang, Zhao
    Zhang, Tao
    Ma, Xindi
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (06) : 5259 - 5274