Poisoning Detection in Federated Learning System: An Adaptive Approach

Anze Cheng, Lin Qi, Liangyu Lv, Siyuan Gao, Zhaoming Li · 2023

There are two key challenges in artificial intelligence electronic medical diagnosis systems: data silos and privacy security. More and more electronic medical systems are choosing federated learning frameworks in the modeling process. However, malicious third parties join the federated learning process as data holders and launch poisoning attacks on the global model, which brings new security challenges to electronic medical systems based on federated learning. Most of the current anti-poisoning methods rely on estimating the number of poisoned nodes, but methods that do not estimate the number of poisoned nodes lack stability. This paper studies existing defense methods and designs a new algorithm for poisoning detection of computing node parameters based on weight distribution that does not rely on prior knowledge of poisoned nodes. On this basis, an adaptive optimizer is designed to solve the stability problem of poisoning detection. The experiment was tested on a sleep posture recognition dataset. Our method can still maintain good stability under attacks with infection rates as high as 50%, and can achieve over 94% accuracy under poisoning attacks.

Read the paper · More papers on PaperTik