Byzantine-Robust Federated Learning on Non-IID Data via Inversing Artificial Gradients
Minyang Li, Xiangyun Tang, Tao Zhang, Guangyuan Liu, Yu Weng · 2024
Federated Learning (FL) is a distributed machine learning framework that enhances privacy by enabling multiple participants to train a global model without sharing their raw data. However, FL still faces the threat posed by data and Byzantine attacks (e.g., data poisoning and model poisoning attacks) from malicious clients aimed to decrease the FL global training accuracy. Previous studies have proposed solutions to improve the robustness of FL systems. However, these robust approaches have not effectively defended against Byzantine attacks from malicious clients in non-Independent and Identically Distributed (non-IID) environments, decreasing overall training accuracy. In this work to address this issues, we propose a new defence framework that aims to enhance model accuracy against Byzantine attacks from malicious clients in non-IID environments. In our approach, the central server performs the Inverse Deep Learning Gradient attack using the gradient data submitted by users in each round, obtaining an inversed artificial gradient. We then assess the squared L2 norm difference between this inversed gradient and the actual gradients to detect malicious clients. Simultaneously, we assign weights to each client involved in the aggregation based on differences in the squared L2 norm, aiming to minimize the impact of malicious actors on the overall model. We have experimentally evaluated our method and demonstrated its ability to maintain training accuracy under attack in non-IID environments using standard datasets.