Poisoning Attacks Against Non-IID Federated Learning with Mixed-Data Calibration

Xufei Zhang, Suleyman Uludag · 2024

Federated Learning (FL) is a privacy-preserving and collaborative machine learning approach that enables de-centralized data utilization across multiple clients. However, the performance of the global model can be compromised by the presence of non-independent and non-identically distributed (non-IID) data among clients. Various calibration methods, in-cluding Mixed Data Calibration (MIDAC), have been proposed to address these challenges by improving the global model's accuracy. Despite their advantages, these methods introduce a new vulnerability: calibration data-poisoning attacks. To the best of our knowledge, our work is the first to study such attacks. This paper investigates the impact of calibration data-poisoning on FL systems using MIDAC. Through extensive experimentation with the CIFAR-10 dataset, we demonstrate that as the percentage of poisoned calibration data increases, the global model's accuracy significantly decreases. Furthermore, we show that increasing the size of the calibration dataset can mitigate some of the adverse effects of poisoned data. These findings highlight the urgent need for robust mechanisms to defend against calibration data-poisoning attacks, ensuring the security and reliability of FL systems using calibration methods.

Read the paper · More papers on PaperTik