Detecting Diverse Poisoning Attacks in Federated Learning Based on Joint Similarity

Jieyi Deng, Siying Liu, Congduan Li · 2024

Federated Learning (FL) can combine information from multiple parties and does not require clients to upload their local privacy data, which pays a vital role in protecting privacy information of clients. However, some malicious clients exploit vulnerabilities in Federated Learning system, attempting to undermine its performance by contaminating local data or model parameter, known as poisoning. Our proposed method, Federated Learning Poisoning Defense System (FLPD), can identify potential poisoning attackers using joint similarity. Additionally, rather than directly removing the attackers, we adjust its weight and rectify its gradient. This approach not only minimizes the impact of the attackers but also leverages their gradient diversity to enhance convergence speed. We conduct experiments under multiple attack scenarios and find that our method generally achieves higher detection accuracy compared to existing approaches.

Read the paper · More papers on PaperTik