Federated learning, as a novel machine learning paradigm, achieves distributed model training while preserving client data privacy. However, under the distributed architecture, due to factors such as client manipulability and weaker aggregation algorithms, federated learning faces security threats at various stages. Among these, model poisoning attacks occur during the training phase, where attackers impersonate benign clients and upload malicious model gradients to the server for aggregation, resulting in a decline in global model performance. Existing aggregation methods for defending against model poisoning attacks only exhibit superior performance when the number of malicious clients is small or when targeting a specific attack method. To address this, we have designed a general defensive aggregation method, DefMPA, that does not rely on the number of malicious clients. DefMPA predicts model updates using the Cauchy mean value theorem, where malicious model updates will significantly differ from the predicted updates. Subsequently, the DBSCAN clustering method is employed to identify malicious model updates. Moreover, DefMPA implements a trust score mechanism that dynamically adjusts each client’s contribution, weakening the influence of malicious model updates on the global model and reducing the attack’s effectiveness. Extensive experiments demonstrate that DefMPA achieves an overall detection success rate of around 90 \(\%\) against three different attacks. Furthermore, as the number of malicious clients increases, DefMPA maintains more stable global model accuracy compared to five mainstream aggregation algorithms.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

DefMPA: Defending Model Poisoning Attacks in Federated Learning via Model Update Prediction

  • Mengya Guo,
  • Bing Chen,
  • Baolu Xue,
  • Jiewen Liu

摘要

Federated learning, as a novel machine learning paradigm, achieves distributed model training while preserving client data privacy. However, under the distributed architecture, due to factors such as client manipulability and weaker aggregation algorithms, federated learning faces security threats at various stages. Among these, model poisoning attacks occur during the training phase, where attackers impersonate benign clients and upload malicious model gradients to the server for aggregation, resulting in a decline in global model performance. Existing aggregation methods for defending against model poisoning attacks only exhibit superior performance when the number of malicious clients is small or when targeting a specific attack method. To address this, we have designed a general defensive aggregation method, DefMPA, that does not rely on the number of malicious clients. DefMPA predicts model updates using the Cauchy mean value theorem, where malicious model updates will significantly differ from the predicted updates. Subsequently, the DBSCAN clustering method is employed to identify malicious model updates. Moreover, DefMPA implements a trust score mechanism that dynamically adjusts each client’s contribution, weakening the influence of malicious model updates on the global model and reducing the attack’s effectiveness. Extensive experiments demonstrate that DefMPA achieves an overall detection success rate of around 90 \(\%\) against three different attacks. Furthermore, as the number of malicious clients increases, DefMPA maintains more stable global model accuracy compared to five mainstream aggregation algorithms.