Federated learning enables learning from decentralized data sources without compromising privacy, which makes it a crucial technique. However, it is vulnerable to model poisoning attacks, where malicious clients interfere with the training process. Previous defense mechanisms have focused on the server-side by using careful model aggregation, but this may not be effective when the data is not identically distributed or when attackers can access the information of benign clients. In this paper, we propose a new defense mechanism that focuses on the client-side, called FedDefender, to help benign clients train robust local models and avoid the adverse impact of malicious model updates from attackers, even when a server-side defense cannot identify or remove adversaries. Our method consists of two main components: (1) attack-tolerant local meta update and (2) attack-tolerant global knowledge distillation. These components are used to find noise-resilient model parameters while accurately extracting knowledge from a potentially corrupted global model. Our client-side defense strategy has a flexible structure and can work in conjunction with any existing server-side strategies. Evaluations of real-world scenarios across multiple datasets show that the proposed method enhances the robustness of federated learning against model poisoning attacks.
翻译:联邦学习能够在保护隐私的前提下从分散的数据源中学习,这使得它成为一项关键技术。然而,它容易受到模型投毒攻击,恶意客户端会干扰训练过程。以往的防御机制侧重于服务器端,通过谨慎的模型聚合来实现,但当数据分布非独立同分布或攻击者能够获取良性客户端信息时,这种方法可能无效。本文提出了一种新的客户端侧防御机制FedDefender,帮助良性客户端训练鲁棒的本地模型,并避免攻击者恶意模型更新的不良影响,即使服务器端防御无法识别或移除敌手。我们的方法包含两个主要组件:(1)容忍攻击的本地元更新和(2)容忍攻击的全局知识蒸馏。这些组件用于寻找抗噪声的模型参数,同时从可能被破坏的全局模型中准确提取知识。我们的客户端侧防御策略结构灵活,可与任何现有服务器端策略协同工作。跨多个数据集的真实场景评估表明,所提方法增强了联邦学习对模型投毒攻击的鲁棒性。