CodeNexa: A Novel Security Framework for Federated Learning to Mitigate Man-in-the-Middle Attacks
B.L.H. Peiris D, J.P.A.S. Pathmendre, A.R.W.M. Hasaranga, a b, Kanishka Yapa, Samadhi Chathuranga Rathnayake · 2024
Federated learning is a decentralized approach that enables collaborative model training across multiple nodes without sharing raw data. While this paradigm enhances privacy, it introduces significant security challenges, particularly against man-in-the-middle (MITM) attacks. This paper presents CodeNexa, a novel security framework designed to mitigate MITM attacks in federated learning environments. Unlike traditional methods such as hash functions, digital signatures, and watermarking, CodeNexa employs a dynamic metric verification mechanism. This mechanism involves calculating and securely storing critical evaluation metrics, including accuracy, precision, recall, and Area Under the Curve (AUC), to six decimal places. These metrics are later used to verify the integrity of model updates during aggregation, ensuring that only legitimate model updates are accepted. Extensive experiments conducted on the MNIST dataset demonstrate CodeNexa’s ability to detect and reject compromised model weights, significantly reducing the risk of model poisoning and unauthorized alterations. The proposed method enhances the robustness of federated learning models while offering a scalable and adaptable solution to emerging threats. CodeNexa’s continuous model integrity verification across distributed nodes makes it a compelling choice for securing federated learning systems in various real-world applications.