WMDefense: Using Watermark to Defense Byzantine Attacks in Federated Learning

被引:15
作者
Zheng, Xu [1 ]
Dong, Qihao [1 ]
Fu, Anmin [1 ]
机构
[1] Nanjing Univ Sci & Technol, Sch Comp Sci & Engn, Nanjing, Peoples R China
来源
IEEE INFOCOM 2022 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS) | 2022年
基金
中国国家自然科学基金;
关键词
Byzantine attacks; Federated learning; Model poisoning attacks; Deep Neural Networks watermarking;
D O I
10.1109/INFOCOMWKSHPS54753.2022.9798217
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Federated learning enables data owners to train a global ML model without exchanging data. However, the unique pattern of training in federated learning can be exploited by malicious adversaries. These malicious adversaries degrade the accuracy of the federated training model by sending malicious inputs during the federated training process. Existing Byzantine robust federated learning algorithms remain vulnerable to customized local model poisoning attacks because they are not designed with a suitable malicious client detection mechanism. To defend against the latest Byzantine attacks, this work proposes an effective algorithm, WMDefense, which identifies malicious clients by embedding a watermark to the global model and tracking the degree of watermark recession after local model training. Our experiments apply WMDefense to two recent Byzantine attack algorithms and validate them using two publicly available datasets, showing that it can defend well against both attacks. Furthermore, we compare WMDefense with two current state-of-the-art Byzantine robustness federated learning algorithms and show our superior performance.
引用
收藏
页数:6
相关论文
共 23 条
  • [1] Bagdasaryan E, 2020, PR MACH LEARN RES, V108, P2938
  • [2] Baruch M., 2019, Advances in Neural Information Processing Systems
  • [3] Bhagoji AN, 2019, PR MACH LEARN RES, V97
  • [4] Blanchard P, 2017, ADV NEUR IN, V30
  • [5] FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping
    Cao, Xiaoyu
    Fang, Minghong
    Liu, Jia
    Gong, Neil Zhenqiang
    [J]. 28TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2021), 2021,
  • [6] Chen Yudong, 2017, ACM MEAS ANAL COMPUT, V1
  • [7] Secure Collaborative Deep Learning Against GAN Attacks in the Internet of Things
    Chen, Zhenzhu
    Fu, Anmin
    Zhang, Yinghui
    Liu, Zhe
    Zeng, Fanjian
    Deng, Robert H.
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (07) : 5839 - 5849
  • [8] El Mhamdi El Mahdi, 2018, P MACHINE LEARNING R, V80
  • [9] Fang MH, 2020, PROCEEDINGS OF THE 29TH USENIX SECURITY SYMPOSIUM, P1623
  • [10] VFL: A Verifiable Federated Learning With Privacy-Preserving for Big Data in Industrial IoT
    Fu, Anmin
    Zhang, Xianglong
    Xiong, Naixue
    Gao, Yansong
    Wang, Huaqun
    Zhang, Jing
    [J]. IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (05) : 3316 - 3326