arrow
返回

Shielding Collaborative Learning: Mitigating Poisoning Attacks Through Client-Side Detection

delete2020-01-01
delete75
delete
OA
AI
L
Lingchen Zhao
胡胜山 (Shengshan Hu)
王茜 封面图
王茜 (Qian Wang) *
J
Jianlin Jiang
S
Shen Chao
X
Xiangyang Luo
胡鹏飞 (Pengfei Hu)
DOI:10.1109/TDSC.2020.2986205delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
Collaborative learning allows multiple clients to train a joint model without sharing their data with each other. Each client performs training locally and then submits the model updates to a central server for aggregation. Since the server has no visibility into the process of generating the updates, collaborative learning is vulnerable to poisoning attacks where a malicious client can generate a poisoned update to introduce backdoor functionality to the joint model. The existing solutions for detecting poisoned updates, however, fail to defend against the recently proposed attacks, especially in the non-IID (independent and identically distributed) setting. In this article, we present a novel defense scheme to detect anomalous updates in both IID and non-IID settings. Our key idea is to realize client-side cross-validation, where each update is evaluated over other clients' local data. The server will adjust the weights of the updates based on the evaluation results when performing aggregation. To adapt to the unbalanced distribution of data in the non-IID setting, a dynamic client allocation mechanism is designed to assign detection tasks to the most suitable clients. During the detection process, we also protect the client-level privacy to prevent malicious clients from knowing the participations of other clients, by integrating differential privacy with our design without degrading the detection performance. Our experimental evaluations on three real-world datasets show that our scheme is significantly robust to two representative poisoning attacks.
Keyword:
Collaborative work
Data models
Servers
Computational modeling
Training
Task analysis
Training data
Poisoning attack
collaborative learning
deep learning
privacy
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

IEEE Transactions on Dependable and Secure Computing 封面图
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
论文数:
2.4K
被引数:
9.6K

机构

X
xi'an jiaotong university
学者数:
9.3W
论文数: 6.7W
被引数: 75
P
pla information engineering university
学者数:
2.8K
论文数: 1.6K
被引数: 2
W
wuhan university
学者数:
8.1W
论文数: 5.8W
被引数: 70
学者 查看更多机构
引用论文

引用论文

Adversarial Examples for Automatic Speech Recognition: Attacks and Countermeasures
err2019-10-01
err34
PREAI
errHu, Shengshan; Shang, Xingcan; Qin, Zhan; Li, Minghui; Wang, Qian; Wang, Cong
err分享
err收藏
Invisible Adversarial Attack against Deep Neural Networks: An Adaptive Penalization Approach
err2019-01-01
err26
PREAI
errWang, Zhibo; Song, Mengkai; Zheng, Siyan; Zhang, Zhifei; Song, Yang; Wang, Qian
err分享
err收藏
学者 查看更多内容