Towards Unified, Practical Evaluation of Model Poisoning Attacks and Defence in Federated Learning
Han Yang, Dongbing Gu, Jianhua He · 2023
Federated learning (FL) is an efficient and privacy-preserving technology which can be applied to 6G networks. However, FL is known to be vulnerable to model poisoning attacks, which hamper the accuracy of the aggregated model by sending malicious updates during the FL training process. While existing algorithms such as byzantine-robust FL have been proposed to defend against targeted poisoning attacks, which misclassify samples with preset triggers, there are very few works on defending against untargeted poisoning attacks. In this work, we first present a unified and reformulated framework for existing untargeted poisoning attacks, which aim to minimize the accuracy of the global model without chosen triggers for targeted labels. Then, we propose FedDet, a median-based re-weighting aggregation algorithm, to defend the untargeted attacks. To test the security performance of FedDet, six adaptive untargeted poisoning attacks tailored to FedDet are designed. We evaluate the performance of FedDet against these attacks under the benchmark dataset. Experiment results demonstrate that FedDet is robust against untargeted attacks and can maintain high global model accuracy.