Federated learning (FL) systems are vulnerable to malicious clients that submit poisoned local models to achieve their adversarial goals, such as preventing the convergence of the global model or inducing the global model to misclassify some data. Many existing defense mechanisms are impractical in real-world FL systems, as they require prior knowledge of the number of malicious clients or rely on re-weighting or modifying submissions. This is because adversaries typically do not announce their intentions before attacking, and re-weighting might change aggregation results even in the absence of attacks. To address these challenges in real FL systems, this paper introduces a cutting-edge anomaly detection approach with the following features: i) Detecting the occurrence of attacks and performing defense operations only when attacks happen; ii) Upon the occurrence of an attack, further detecting the malicious client models and eliminating them without harming the benign ones; iii) Ensuring honest execution of defense mechanisms at the server by leveraging a zero-knowledge proof mechanism. We validate the superior performance of the proposed approach with extensive experiments.
翻译:联邦学习(FL)系统容易受到恶意客户端的攻击,这些客户端提交被毒化的局部模型以达到其对抗性目标,例如阻止全局模型收敛或诱导全局模型对某些数据进行错误分类。许多现有的防御机制在实际FL系统中不实用,因为它们需要事先了解恶意客户端的数量,或依赖于重新加权或修改提交。这是因为对手通常不会在攻击前宣布其意图,而重新加权即使在无攻击情况下也可能改变聚合结果。为应对真实FL系统中的这些挑战,本文引入了一种前沿的异常检测方法,具有以下特点:i) 仅在攻击发生时检测攻击并执行防御操作;ii) 当攻击发生时,进一步检测恶意客户端模型并将其消除,而不损害良性模型;iii) 通过利用零知识证明机制确保服务器诚实执行防御机制。我们通过大量实验验证了所提出方法的优越性能。