Federated learning (FL) offers a decentralized framework where multiple clients collaborate to train a shared global model without exposing their raw data. However, FL is highly susceptible to data poisoning attacks, where malicious clients introduce adversarial or corrupted data into their local training sets. These poisoned updates, when aggregated into the global model, can degrade the model’s performance. This paper proposes a defense mechanism using Generative Adversarial Networks (GANs) to detect poisoned updates in FL. The generator simulates a wide range of poisoned data patterns, while the discriminator identifies and flags malicious updates in real-time without requiring access to the clients’ raw data. Our GAN-based framework offers adaptability by handling both targeted and untargeted poisoning attacks. Additionally, a continuous feedback loop is introduced, where flagged poisoned updates are logged and used to further refine the GAN’s detection capabilities. This adaptive system ensures robust protection of FL models while maintaining data privacy and security.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Adaptive GAN-Based Defense Against Data Poisoning in Federated Learning

  • Poshak Pathak,
  • Prasanthi Sreekumari

摘要

Federated learning (FL) offers a decentralized framework where multiple clients collaborate to train a shared global model without exposing their raw data. However, FL is highly susceptible to data poisoning attacks, where malicious clients introduce adversarial or corrupted data into their local training sets. These poisoned updates, when aggregated into the global model, can degrade the model’s performance. This paper proposes a defense mechanism using Generative Adversarial Networks (GANs) to detect poisoned updates in FL. The generator simulates a wide range of poisoned data patterns, while the discriminator identifies and flags malicious updates in real-time without requiring access to the clients’ raw data. Our GAN-based framework offers adaptability by handling both targeted and untargeted poisoning attacks. Additionally, a continuous feedback loop is introduced, where flagged poisoned updates are logged and used to further refine the GAN’s detection capabilities. This adaptive system ensures robust protection of FL models while maintaining data privacy and security.