Fair Detection of Poisoning Attacks in Federated Learning

被引:11
作者
Singh, Ashneet Khandpur [1 ]
Blanco-Justicia, Alberto [1 ]
Domingo-Ferrer, Josep [1 ]
Sanchez, David [1 ]
Rebollo-Monedero, David [1 ]
机构
[1] Univ Rovira & Virgili, Dept Comp Engn & Math, CYBERCAT Ctr Cybersecur Res Catalonia, UNESCO Chair Data Privacy, Av Paisos Catalans 26, E-43007 Tarragona, Catalonia, Spain
来源
2020 IEEE 32ND INTERNATIONAL CONFERENCE ON TOOLS WITH ARTIFICIAL INTELLIGENCE (ICTAI) | 2020年
基金
欧盟地平线“2020”;
关键词
Federated learning; Security; Privacy; Fairness;
D O I
10.1109/ICTAI50040.2020.00044
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning is a decentralized machine learning technique that aggregates partial models trained by a set of clients on their own private data to obtain a global model. This technique is vulnerable to security attacks, such as model poisoning, whereby malicious clients submit bad updates in order to prevent the model from converging or to introduce artificial bias in the classification. Applying anti-poisoning techniques might lead to the discrimination of minority groups whose data are significantly and legitimately different from those of the majority of clients. In this work, we strive to strike a balance between fighting poisoning and accommodating diversity to help learning fairer and less discriminatory federated learning models. In this way, we forestall the exclusion of diverse clients while still ensuring detection of poisoning attacks. Empirical work on a standard machine learning data set shows that employing our approach to tell legitimate from malicious updates produces models that are more accurate than those obtained with standard poisoning detection techniques.
引用
收藏
页码:224 / 229
页数:6
相关论文
共 50 条
[41]   DeSMP: Differential Privacy-exploited Stealthy Model Poisoning Attacks in Federated Learning [J].
Hossain, Md Tamjid ;
Islam, Shafkat ;
Badsha, Shahriar ;
Shen, Haoting .
2021 17TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2021), 2021, :167-174
[42]   Two-phase Defense Against Poisoning Attacks on Federated Learning-based Intrusion Detection [J].
Lai, Yuan-Cheng ;
Lin, Jheng-Yan ;
Lin, Ying-Dar ;
Hwang, Ren-Hung ;
Lin, Po-Chin ;
Wu, Hsiao-Kuang ;
Chen, Chung-Kuan .
COMPUTERS & SECURITY, 2023, 129
[44]   Toward Efficient and Certified Recovery From Poisoning Attacks in Federated Learning [J].
Jiang, Yu ;
Shen, Jiyuan ;
Liu, Ziyao ;
Tan, Chee Wei ;
Lam, Kwok-Yan .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 :2632-2647
[45]   A survey on privacy-preserving federated learning against poisoning attacks [J].
Xia, Feng ;
Cheng, Wenhao .
CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (10) :13565-13582
[46]   DeMAC: Towards detecting model poisoning attacks in federated learning system [J].
Yang, Han ;
Gu, Dongbing ;
He, Jianhua .
INTERNET OF THINGS, 2023, 23
[47]   Collusion-Based Poisoning Attacks Against Blockchained Federated Learning [J].
Zhang, Xiaohui ;
Shen, Tao ;
Bai, Fenhua ;
Zhang, Chi .
IEEE NETWORK, 2023, 37 (06) :50-57
[48]   DUPS: Data poisoning attacks with uncertain sample selection for federated learning [J].
Zhang, Heng-Ru ;
Wang, Ke-Xiong ;
Liang, Xiang-Yu ;
Yu, Yi-Fan .
COMPUTER NETWORKS, 2025, 256
[49]   FEDCLEAN: A DEFENSE MECHANISM AGAINST PARAMETER POISONING ATTACKS IN FEDERATED LEARNING [J].
Kumar, Abhishek ;
Khimani, Vivek ;
Chatzopoulos, Dimitris ;
Hui, Pan .
2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, :4333-4337
[50]   Precision Guided Approach to Mitigate Data Poisoning Attacks in Federated Learning [J].
Kumar, K. Naveen ;
Mohan, C. Krishna ;
Machiry, Aravind .
PROCEEDINGS OF THE FOURTEENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, CODASPY 2024, 2024, :233-244