Zero Knowledge Clustering Based Adversarial Mitigation in Heterogeneous Federated Learning

被引:65
作者
Chen, Zheyi [1 ]
Tian, Pu [1 ]
Liao, Weixian [1 ]
Yu, Wei [1 ]
机构
[1] Towson Univ, Dept Comp & Informat Sci, Towson, MD 21252 USA
来源
IEEE TRANSACTIONS ON NETWORK SCIENCE AND ENGINEERING | 2021年 / 8卷 / 02期
基金
美国国家科学基金会;
关键词
Training; Servers; Peer-to-peer computing; Machine learning; Data models; Security; Distributed databases; Non-i; i; d; data; adversarial mitigation; federated learning; NETWORKS; INTERNET; IOT;
D O I
10.1109/TNSE.2020.3002796
中图分类号
T [工业技术];
学科分类号
08 ;
摘要
The simultaneous development of deep learning techniques and Internet of Things (IoT)/Cyber-physical Systems (CPS) technologies has afforded untold possibilities for improving distributed computing, sensing, and data analysis. Among these technologies, federated learning has received increased attention as a privacy-preserving collaborative learning paradigm, and has shown significant potential in IoT/CPS-driven large-scale smart-world systems. At the same time, the vulnerabilities of deep neural networks, especially to adversarial attacks, cannot be overstated and should not be minimized. Moreover, the distributed nature of federated learning makes defense against such adversarial attacks a more challenging problem due to the unavailability of local data and resource heterogeneity. To tackle these challenges, in this paper, we propose ZeKoC, a Zero Knowledge Clustering approach to mitigating adversarial attacks. Particularly, we first formulate the problem of resource-constrained adversarial mitigation. Specifically, noting that a global server has no access to training samples, we reformulate the unsupervised weight clustering problem. Our proposed ZeKoC approach allows the server to automatically split and merge weight clusters for weight selection and aggregation. Theoretical analysis demonstrates that convergence is guaranteed. Further, our experimental results illustrate that, in a non-i.i.d. (i.e., independent and identically distributed) data setting, the proposed ZeKoC approach successfully mitigates general attacks while outperforming state-of-art schemes.
引用
收藏
页码:1070 / 1083
页数:14
相关论文
共 42 条
[1]  
Bagdasaryan E, 2018, arXiv
[2]  
Baruch M, 2019, ADV NEUR IN, V32
[3]  
Bhagoji AN, 2019, PR MACH LEARN RES, V97
[4]  
Bonawitz K. A., 2019, Machine Learning and Systems, V1, P374
[5]   Federated learning of predictive models from federated Electronic Health Records [J].
Brisimi, Theodora S. ;
Chen, Ruidi ;
Mela, Theofanie ;
Olshevsky, Alex ;
Paschalidis, Ioannis Ch. ;
Shi, Wei .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2018, 112 :59-67
[6]  
Cohen G, 2017, IEEE IJCNN, P2921, DOI 10.1109/IJCNN.2017.7966217
[7]  
Hatcher W. G., IEEE ACCESS, V6
[8]  
Hsieh K, 2020, PR MACH LEARN RES, V119
[9]   Data clustering: 50 years beyond K-means [J].
Jain, Anil K. .
PATTERN RECOGNITION LETTERS, 2010, 31 (08) :651-666
[10]  
Jain Anil K., 1988, Algorithms for Clustering Data