FLForest: Byzantine-robust Federated Learning through Isolated Forest
Tao Wang, Bo Zhao, Liming Fang · 2023
Federated learning (FL) is a privacy-preserving distributed machine learning technique that allows clients to jointly train a global model under the coordination of cloud server. However, malicious clients can corrupt the global model to predict incorrect labels for testing examples. Currently, existing mainstream Byzantine-robust FL methods are vulnerable to various adaptive attacks, and violates the privacy principle of FL. Moreover, these schemes will be less robust in the face of targeted poisoning attacks with few samples and data distributions that are highly non-independent and identically distributed(non-IID). In this work, to address these issues, we propose a novel Byzantine-robust FL framework based on Isolated Forest. Specifically, before the start of each round, FLForest will calculate the divergences between the model update and the model update of the previous round to decide whether to activate the defense. After that, FLForest trains an isolated forest based on model updates after after dimensionality reduction. Model updates isolated with fewer splits will be considered as malicious model updates and excluded from the global model’s aggregation. Extensive experiments demonstrate that FLForest achieves better performance compared to baseline methods under highly non-IID distribution.