Analyzing Poisoning Attacks on Non-IID Federated Learning Systems for Credit Scoring

Aman Patil, Adesh Choudhar, Darshan Shah, Jibi Abraham, Apeksha Bochare · 2024

Federated learning (FL) is a technique that allows decentralized model training on local datasets, removing the necessity to deliver the data to a coordinator. In contrast to conventional methods where data is collected and centralized, federated learning enables credit bureaus to construct credit ratings using a distributed approach. In this approach, a global model is trained by aggregating localized models from edge devices (smartphones or IoT devices located closer to the data or the runner). Despite the advantages of federated learning over centralized methods, the open training environment and exposed model parameters make it vulnerable to malicious poisoning attacks. Various poisoning attacks encompassing label-flipping, clean-label, model and data poisoning, have the potential to compromise the integrity and efficacy of federated learning systems. This research study sheds light on the utilization of federated learning for credit score prediction, highlighting the effects of poisoning attacks on learning metrics. By better understanding these attacks and their impact, enhanced strategies to detect and mitigate such threats, safeguarding the integrity of federated learning systems in various domains can be devised. A credit scoring system is implemented based on the decentralized approach of federated learning using a non-IID dataset. The impact of changing parameters, such as the quantity of runners and attack percentage on learning metrics for three types of attacks, viz., label-flipping, Byzantine, and data poisoning are observed.

Read the paper · More papers on PaperTik