Hybridized Shield: A Framework for Backdoor Detection in Secure Federated Learning Systems
Gul Rahman, Saeed-uz-zaman, Bin Li, Junaid Hussain Muzamal · 2024
In the context of Federated Learning, the vulnerability to backdoor attacks poses a significant threat to the integrity and reliability of distributed learning systems. This research introduces a novel defense framework, the” Hybridized Shield,” designed to safeguard Federated Learning environments robustly against such insidious threats. The proposed mechanism integrates Oblivious Random Grouping, Partial Parameter Disclosure, and differential outlier analysis, forming a comprehensive defense strategy that addresses the unique challenges of Federated Learning’s decentralized and collaborative nature. The results reveal a significant improvement in the resilience of Federated Learning systems against backdoor attacks. Specifically, the proposed method maintains high accuracy on clean data ($\mathbf{9 7. 9 2 \%}$ on MNIST and CIFAR-10) while significantly reducing the effectiveness of poisoned data attacks to a mere $\mathbf{1 0. 1 1 \%}$ accuracy, compared to the baseline Federated Learning model without defense mechanisms, which showed a $100 \%$ accuracy on poisoned data and an $18.56 \%$ attack success rate. These findings underscore the efficacy of the” Hybridized Shield” in preserving the integrity and security of Federated Learning systems, thereby contributing to the advancement of secure and reliable distributed machine learning methodologies.