A Data Poisoning Resistible and Privacy Protection Federated-Learning Mechanism for Ubiquitous IoT
Gengxiang Chen, Xiaoyi Li, Linlin You, Ahmed M. Abdelmoniem, Yan Zhang, Chau Yuen · IEEE Internet of Things Journal · 2024
As a novel distributed learning paradigm, federated learning (FL) allows clients to train global models collaboratively without exchanging private data. However, recent research not only demonstrates the vulnerability of FL against privacy attacks where adversaries try to recover private data by intercepting local gradients/models but also its inadequacy in defending against poisoning attacks launched by malicious adversaries, who modify local datasets to disrupt the global training process. Even though many solutions have been proposed to defend against these attacks, there is still a gap in mitigating the risks in more complex nonindependent and identically distributed (Non-IID) scenarios that are prevalent in Internet of Things (IoT) systems. To fill this gap, this article proposes a data poisoning resistible and privacy protection FL mechanism (DPR-PPFL) for ubiquitous IoT. Based on representational similarity analysis, DPR-PPFL allows clients to construct asymmetric local models in defending against data inversion attacks, and also the server to detect and aggregate benign local models uploaded by the clients to correctly train the global model in the face of data poisoning attacks. By comparing the performance of DPR-PPFL with state-of-the-art baselines, its merits in securing the learning process under IID and Non-IID scenes of IoT are demonstrated.