AsyncFilter: Detecting Poisoning Attacks in Asynchronous Federated Learning

Yufei Kang, Baochun Li · 2024

Federated learning has garnered substantial research attention as a privacy-preserving learning paradigm. Nonetheless, its inherently distributed architecture, especially in asynchronous settings, poses vulnerabilities to model poisoning attacks. In such scenarios, malicious clients compromise the integrity of the global model by transmitting manipulated updates. To tackle this issue, previous research efforts like AFLGuard and Zeno++ have made strides but often hinge on the impractical assumption that the server has access to a clean dataset. In this study, we delve into practical solutions tailored for real-world scenarios, minimizing assumptions about the server's capabilities and accommodating varying settings. Specifically, we propose AsyncFilter module, which defends against poisoning attacks in asynchronous federated learning. Functioning as a plug-and-play module on the server, AsyncFilter enhances the learning process by statistically identifying and filtering out poisoned updates during training. On four real-world datasets, AsyncFilter effectively enhances global model accuracy against model poisoning attacks by up to 7%, 20%, 16% and 39% respectively. Through extensive evaluation, AsyncFilter demonstrates robust capabilities in detecting and mitigating model poisoning attacks in various scenarios encompassing diverse data and system heterogeneity, as well as varying attacker presence.

Read the paper · More papers on PaperTik