Community-Oriented Duplex Privacy Amplification and Active Poisoning Resistance for Heterogeneous Federated Learning

Zan Zhou, Jun Zhao, Shujie Yang, Hongjing Li, Tengchao Ma, Changqiao Xu · IEEE Transactions on Dependable and Secure Computing · 2025

Privacy protection and poisoning resilience are important concerns for federated learning (FL). During a relatively long period, the corresponding solutions are regarded as orthogonal and investigated separately. Unfortunately, due to the increasingly complex structure and ever-growing parameter dimensions of the models to be trained, the forthright coupling of existing differential privacy and Byzantine resilience techniques has been proved incompatible with FL. This emerging problem prompts us to give serious thought to jointly guaranteeing data privacy and model integrity. Besides, worse still, the multi-task characteristic and data imbalance of heterogeneous FL inevitably introduce huge variances, which make privacy-preserving under acceptable accuracy loss even more complicated, not to mention efficient and agile poisoning resistance. Against this bothersome situation, we propose a community-oriented secure heterogeneous FL (CoS-HFL) framework to provide guaranteed privacy protection and significant model robustness simultaneously. CoS-HFL includes two parts: community-oriented duplex privacy amplification and credit-based poisoning resistance. The former copes with potential leakage threats with both uplink and downlink obfuscations. The latter further actively thwarts poisoning attacks based on credibility evaluation. Furthermore, we conduct experiments on benchmark datasets to highlight the performance of CoS-HFL in terms of privacy amplification, poisoning resistance, and learning accuracy under adversarial and heterogeneous environments.

Read the paper · More papers on PaperTik