Enhancing Federated Learning Security: Combating Clients’ Data Poisoning with Classifier Ensembles

Arunava Roy, Dipankar Dasgupta · 2024

Federated Learning (FL) enables decentralized model training while preserving data privacy, but it is vulnerable to data poisoning attacks where adversaries manipulate local data to compromise the global model. To address this, we propose a robust defense using an Ensemble of Classifiers (EoCl), a lightweight global input defense mechanism against clients’ data poisoning. The EoCl is trained centrally at the CAS and distributed to clients, filtering corrupted data before it affects local models. This approach reduces the computational load on clients while enhancing their private data security and model accuracy. We recommend regularly updating the global EoCl by both refining the selection of classifiers and training it on a broader range of datasets. Additionally, it is advisable to periodically refresh the local EoCls on active clients after a predetermined number of global iterations. The timing of these updates can be based on the quality of the clients’ parameter updates and loss values, though the final decision rests with the FL service provider. This adaptive strategy helps to maintain both the accuracy and security of the FL system against clients’ data poisoning attacks. We conducted extensive experiments using a variety of public datasets.

Read the paper · More papers on PaperTik