<p>Federated learning is a distributed machine learning framework that enables multiple clients to collaboratively train a global model without sharing local data. However, the process is vulnerable to disruption by malicious clients, who may inject adversarially manipulated models to undermine the aggregation process. While various robust aggregation methods exist, many struggle with detection stability and model robustness under diverse poisoning attacks or adversarial-majority scenarios. To address these limitations, we propose RSDFL, a Robust Similarity-based Dual-gradient Federated Learning model, designed to detect and defend against Byzantine attacks. RSDFL effectively identifies malicious clients even under adversarial-majority conditions and ensures the accuracy and reliability of the global model. The approach incorporates a gradient evaluation method based on class loss changes to determine benign and malicious update directions. Additionally, a bidirectional gradient similarity-based credibility metric is introduced to assess the quality of the clients’ training results, forming the basis for a poisoning detection mechanism and robust global model aggregation algorithm. Compared with the most advanced robust federated learning algorithms currently available, experimental results on the F-MNIST, E-MNIST, PathMNIST, and CIFAR-10 datasets demonstrate that our scheme outperforms state-of-the-art methods in terms of Byzantine client identification accuracy and model performance. The model performance approaches the ideal level observed in non-poisoned scenarios. Particularly in the highly challenging adversarial-majority scenario, our scheme effectively mitigates various poisoning attacks that are difficult for existing algorithms to handle, while also exhibiting superior performance in model convergence speed and stability. These results demonstrate the exceptional robustness of our scheme in complex adversarial environments.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Byzantine-robust federated learning against adversarial–majority attacks

  • Yinglong Shi,
  • Xiaoming Hu,
  • Shuangjie Bai,
  • Yan Liu,
  • Hao Lin

摘要

Federated learning is a distributed machine learning framework that enables multiple clients to collaboratively train a global model without sharing local data. However, the process is vulnerable to disruption by malicious clients, who may inject adversarially manipulated models to undermine the aggregation process. While various robust aggregation methods exist, many struggle with detection stability and model robustness under diverse poisoning attacks or adversarial-majority scenarios. To address these limitations, we propose RSDFL, a Robust Similarity-based Dual-gradient Federated Learning model, designed to detect and defend against Byzantine attacks. RSDFL effectively identifies malicious clients even under adversarial-majority conditions and ensures the accuracy and reliability of the global model. The approach incorporates a gradient evaluation method based on class loss changes to determine benign and malicious update directions. Additionally, a bidirectional gradient similarity-based credibility metric is introduced to assess the quality of the clients’ training results, forming the basis for a poisoning detection mechanism and robust global model aggregation algorithm. Compared with the most advanced robust federated learning algorithms currently available, experimental results on the F-MNIST, E-MNIST, PathMNIST, and CIFAR-10 datasets demonstrate that our scheme outperforms state-of-the-art methods in terms of Byzantine client identification accuracy and model performance. The model performance approaches the ideal level observed in non-poisoned scenarios. Particularly in the highly challenging adversarial-majority scenario, our scheme effectively mitigates various poisoning attacks that are difficult for existing algorithms to handle, while also exhibiting superior performance in model convergence speed and stability. These results demonstrate the exceptional robustness of our scheme in complex adversarial environments.