In recent years, Federated Learning (FL) has been making significant progress in many areas. Meanwhile, with the deepening of the study in FL, researchers found that FL is vulnerable to some attacks. Malicious users and server can bring different privacy and security threats. To counter these attacks, a multitude of strategies have been proposed. One approach to aggregation based on validation datasets involves using datasets to verify the models submitted by participants. The accuracy of the models is then assessed to determine if they are malicious. However, all aggregation schemes based on validation datasets require clients to upload plaintext. While ensuring the robustness of the aggregation process, these solutions pose a serious privacy threat, making them infeasible in practice. For the first time, we consider client privacy in the aggregation scheme that uses validation datasets, allowing us to maintain both the aggregation performance and privacy protection. We investigate how to efficiently incorporate fully homomorphic encryption (FHE) into algorithms that use validation datasets. Specifically, We find the approximate polynomial to replace the nonlinear operations in neural network so that it can fit the homomorphic operations, and we use clustering algorithm to split user groups based on the validation scores to determine which group is malicious. Therefore, we propose FedSV based on CKKS and server self-validation. The experimental results show that FedSV can significantly improve the robustness of FL and the error of accuracy with the baseline is kept within 5.7%, even if there is only one benign user.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

FedSV: A Privacy-Preserving Byzantine-Robust Federated Learning Scheme with Self-validation

  • Wenhao Jiang,
  • Shaojing Fu,
  • Yuchuan Luo,
  • Lin Liu,
  • Yongjun Wang

摘要

In recent years, Federated Learning (FL) has been making significant progress in many areas. Meanwhile, with the deepening of the study in FL, researchers found that FL is vulnerable to some attacks. Malicious users and server can bring different privacy and security threats. To counter these attacks, a multitude of strategies have been proposed. One approach to aggregation based on validation datasets involves using datasets to verify the models submitted by participants. The accuracy of the models is then assessed to determine if they are malicious. However, all aggregation schemes based on validation datasets require clients to upload plaintext. While ensuring the robustness of the aggregation process, these solutions pose a serious privacy threat, making them infeasible in practice. For the first time, we consider client privacy in the aggregation scheme that uses validation datasets, allowing us to maintain both the aggregation performance and privacy protection. We investigate how to efficiently incorporate fully homomorphic encryption (FHE) into algorithms that use validation datasets. Specifically, We find the approximate polynomial to replace the nonlinear operations in neural network so that it can fit the homomorphic operations, and we use clustering algorithm to split user groups based on the validation scores to determine which group is malicious. Therefore, we propose FedSV based on CKKS and server self-validation. The experimental results show that FedSV can significantly improve the robustness of FL and the error of accuracy with the baseline is kept within 5.7%, even if there is only one benign user.