FedMSD: Multi-Stage Defense Against Poisoning Attacks in Data Heterogeneous Federated Learning
Xingyu Zhang, Fei Tong, Fangyuan Xing · 2024
Federated Learning (FL) is a novel distributed machine learning approach that focuses on the issue of data silos and ensures privacy protection. Nowadays, FL research is primarily focused on mitigating poisoning attacks in distributed settings. The attacker has the ability to influence numerous clients and submit malicious gradients. The majority of the current research makes the assumption of independent, identically distributed (IID) data scenarios, which restricts their usefulness in heterogeneous data settings. Current defenses can only mitigate a fraction of malicious attacks, as different defense schemes may rely on conflicting assumptions. In order to tackle these challenges, we propose a multi-stage defense mechanism, FedMSD, which can significantly mitigate poisoning attacks in heterogeneous data environments. FedMSD defends against both conspiracy and non-conspiracy attacks. Specifically, we design a cluster attack defense scheme that uses clustering as part of the defense mechanism, making it applicable to data heterogeneity situations. We utilize absolute and relative similarity metrics to filter malicious updates, thus effectively addressing both collusion and non-collusion in poisoning attacks. In addition, we propose a global security aggregation approach that dynamically assigns weights to the global model based on the clusters' reliability. Comprehensive assessments conducted on two standard datasets demonstrate that FedMSD overcomes current defense approaches and offers strong protection against various attacks in heterogeneous data scenarios.