FedGSDW:Enhancing Federated Learning Robustness against Model Poisoning Attack
Shi Xiujin, Naiwen Sun, Gong Jia-wei, Shoujian Yu · 2024
In federated learning, due to its distributed nature, the system is vulnerable to attacks, especially Directed Deviation Attack (DDA), which selectively introduce errors in specific situations by manipulating training data or model parameters to achieve attacker’s specific goals. To address this issue, a defense method called Federated Learning with Cosine Similarity-guided Gradient Splitting and Differential Weighted aggregation(FedGSDW) is proposed, combined with flip-score metric, to improve accuracy of distinguishing benign and malicious clients. In addition, differential aggregation weights are achieved through cosine similarity method and mean aggregation strategy. This method addresses limitations of existing robust aggregation rules and increases impact of benign clients misidentified as malicious in non IID environments as much as possible, while reducing the impact of truly malicious clients as much as possible, helping the global model can learn more about knowledge of benign clients. We trained the model on MNIST, EMNIST, and CIFAR-10 datasets and validated effectiveness of the proposed method. Compared with eight baseline methods including FABA, FoolsGold, FLTrust, and FLAIR, FedGSDW demonstrates better test accuracy in most cases and can effectively improve robustness of federated learning systems in face of model poisoning attack, especially in real world applications where data distribution is non IID.