FL-HSDP: Client-Side Defense for Federated Learning via Hessian Optimization and Shuffled Differential Privacy

Yuting Li, Guojun Wang, Tian Wang, Weijia Jia · 2023

Federated learning (FL) is a prominent paradigm for distributed training that can decrease data leakage by not explicitly sharing private information. Lots of recent research has revealed, however, that malicious clients can easily launch model poisoning attacks and the private information of benign clients can still be divulged in the setting of federated learning. As the existing works are either incapable of providing quantitative privacy for user data or vulnerable to attacks that result in aggregated model misclassifications, we present a framework, FL-HSDP, that uses hessian matrix optimization to creatively involve perturbation into the process of updating gradients for local iterations. Instead of using conventional noise adding method for high-dimensional parameters, we improve the system's performance by employing differential privacy to the regularization term of the Hessian matrix during each local training epoch. In order to further enhance the security of our system, we introduce the privacy amplification effect brought by the shuffler between the clients and server to bolster the confidentiality while minimizing any adverse impact on algorithm performance. The extensive experimental results on FashionMNIST and CIFAR10 datasets demonstrate the effectiveness and efficiency of our approach, almost maintaining the accuracy and effectively mitigating tar-geted model poisoning attack by up to 73.7%. Both the similarity scores and the visualization of the reconstructed images have been demonstrated to be effective against the state-of-the-art weight inversion attacks.

Read the paper · More papers on PaperTik