Defending against Poisoning Attacks in Federated Learning from a Spatial-temporal Perspective
Zhipin Gu, Jiangyong Shi, Yuexiang Yang, Liangzhong He · 2023
In federated learning, the central server aggregates local model updates from the participants in the network to generate a global model. For the purpose of protecting clients' privacy, the server is designed to have no visibility into how these updates are generated. The nature of federated learning makes detecting and defending against malicious model up-dates a challenging task. Unlike existing works that struggle to defend against poisoning attacks from a spatial perspective, the paper considers mitigating the impact of attacks from a spatial-temporal perspective. This paper proposes Fedmvae, a robust federated learning framework. Fedmvae uses multiple variational autoencoder models to detect and exclude malicious model updates from a spatial perspective. Moreover, to handle poisoning attacks with time-varying features, we propose generating a robust global model update according to momentum-based update speculation and historical global updates. Fedmvae is tested with extensive experiments on both IID and non-IID datasets, showing a competitive performance over existing aggregation methods under both Byzantine attacks and backdoor attacks.