FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client Perspective
Federated learning (FL) is a popular distributed learning framework that\ntrains a global model through iterative communications between a central server\nand edge devices. Recent works have demonstrated that FL is vulnerable to model\npoisoning attacks. Several server-based defense approaches (e.g. robust\naggregation), have been proposed to mitigate such attacks. However, we\nempirically show that under extremely strong attacks, these defensive methods\nfail to guarantee the robustness of FL. More importantly, we observe that as\nlong as the global model is polluted, the impact of attacks on the global model\nwill remain in subsequent rounds even if there are no subsequent attacks. In\nthis work, we propose a client-based defense, named White Blood Cell for\nFederated Learning (FL-WBC), which can mitigate model poisoning attacks that\nhave already polluted the global model. The key idea of FL-WBC is to identify\nthe parameter space where long-lasting attack effect on parameters resides and\nperturb that space during local training. Furthermore, we derive a certified\nrobustness guarantee against model poisoning attacks and a convergence\nguarantee to FedAvg after applying our FL-WBC. We conduct experiments on\nFasionMNIST and CIFAR10 to evaluate the defense against state-of-the-art model\npoisoning attacks. The results demonstrate that our method can effectively\nmitigate model poisoning attack impact on the global model within 5\ncommunication rounds with nearly no accuracy drop under both IID and Non-IID\nsettings. Our defense is also complementary to existing server-based robust\naggregation approaches and can further improve the robustness of FL under\nextremely strong attacks.\n
Paper
References (28)
Scroll for more · 16 remaining