Robust Federated Learning: Defence against Model Poisoning using Mean Filtering

Abdul Rehman Omer, Muhammad Shahid Khan, Abdullah Yousafzai · 2024

This research, tries to address a critical issue model poisoning - in federated learning systems, and specifically within the regimes of cross-silo settings. This study introduces a combination of security technique that leverages cosine similarity check and filtering, on the top of, robust aggregation with trimmed mean approach. Federated learning enables multiple devices or organizations - also called silo - to train a collaborative machine learning model without sharing local or private data. Even then, its integrity and security is highly susceptible to model poisoning attacks. In this type of attack, clients with malicious intent send manipulated updates to keep the global model from convergence. To counteract this vulnerability, this study proposes an innovative approach using trimmed mean aggregation and cosine similarity filtering to eliminate the impact of malicious updates. Trimmed mean aggregation mitigates the influence of extreme outlier values before aggregation, thus reducing the impact of potentially poisoned updates. Additionally, cosine similarity filtering assesses the alignment of last layers of aggregated update with that of a trusted reference, filtering out those with low similarity scores. Experiments on benchmark dataset demonstrate that our approach significantly enhances the robustness and efficiency of federated learning models in cross-silo environment when compared to existing methods.

Read the paper · More papers on PaperTik