Label Flipping Attacks on Federated Learning: GAN-Based Poisoning and Countermeasures
Muhammad Abdullah, Vidhatri Bapu, Akash KA, Abdul Hadi Khan, M S Bhargavi · 2024
Federated Learning (FL) is a promising approach for training machine learning models in a decentralized manner to preserve data privacy. However, FL is vulnerable to various attacks, including label-flipping attacks where malicious clients manipulate labels to degrade global model accuracy. This research investigates the efficacy of label-flipping attacks using synthetic images generated by a Generative Adversarial Network (GAN). The GAN architecture and learning procedure are adapted to address challenges related to dataset limitations and ensure realistic data generation for the attacks. The study analyzes the impact of label-flipping attacks on FL model performance. The results demonstrate that these attacks can evade conventional defenses and significantly reduce model accuracy. To mitigate this threat, a novel defense mechanism is proposed to identify and isolate poisoned clients based on abnormally high gradient values. This research highlights the security weaknesses of FL and proposes a defense mechanism against label-flipping attacks. This paves the way for more secure and trustworthy FL applications while preserving data privacy.