FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping

自举(财务) 计算机科学 联合学习 拜占庭式建筑 Byzantine容错 人工智能 分布式计算 计量经济学 数学 考古 历史 容错
作者
Xiaoyu Cao,Minghong Fang,Jia Liu,Neil Zhenqiang Gong
标识
DOI:10.14722/ndss.2021.24434
摘要

Byzantine-robust federated learning aims to enable a service provider to learn an accurate global model when a bounded number of clients are malicious. The key idea of existing Byzantine-robust federated learning methods is that the service provider performs statistical analysis among the clients' local model updates and removes suspicious ones, before aggregating them to update the global model. However, malicious clients can still corrupt the global models in these methods via sending carefully crafted local model updates to the service provider. The fundamental reason is that there is no root of trust in existing federated learning methods. In this work, we bridge the gap via proposing FLTrust, a new federated learning method in which the service provider itself bootstraps trust. In particular, the service provider itself collects a clean small training dataset (called root dataset) for the learning task and the service provider maintains a model (called server model) based on it to bootstrap trust. In each iteration, the service provider first assigns a trust score to each local model update from the clients, where a local model update has a lower trust score if its direction deviates more from the direction of the server model update. Then, the service provider normalizes the magnitudes of the local model updates such that they lie in the same hyper-sphere as the server model update in the vector space. Our normalization limits the impact of malicious local model updates with large magnitudes. Finally, the service provider computes the average of the normalized local model updates weighted by their trust scores as a global model update, which is used to update the global model. Our extensive evaluations on six datasets from different domains show that our FLTrust is secure against both existing attacks and strong adaptive attacks.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
ss完成签到,获得积分10
刚刚
美好眼神完成签到,获得积分10
刚刚
善良画板发布了新的文献求助10
1秒前
1秒前
无色热带鱼完成签到,获得积分10
1秒前
儒雅颜完成签到,获得积分10
1秒前
1秒前
1319472133完成签到,获得积分10
2秒前
JinwenShi完成签到,获得积分10
2秒前
2秒前
Able完成签到,获得积分10
3秒前
我我我发布了新的文献求助10
3秒前
FashionBoy应助lsl采纳,获得10
4秒前
摆渡人完成签到,获得积分10
4秒前
土豪的煎蛋完成签到,获得积分10
4秒前
泡芙完成签到,获得积分10
4秒前
积极的吐司完成签到,获得积分20
5秒前
5秒前
5秒前
Orange应助ouye采纳,获得10
5秒前
安妤完成签到,获得积分10
6秒前
RONG完成签到,获得积分10
6秒前
6秒前
宠仙完成签到,获得积分10
6秒前
6秒前
1304完成签到,获得积分10
7秒前
alabala完成签到,获得积分10
7秒前
苏桑焉完成签到 ,获得积分10
7秒前
Fancy发布了新的文献求助10
8秒前
Lisn发布了新的文献求助50
8秒前
白米饭发布了新的文献求助10
8秒前
香蕉觅云应助X9采纳,获得10
8秒前
alabala发布了新的文献求助10
9秒前
健壮的听兰完成签到,获得积分10
10秒前
10秒前
紫杉完成签到,获得积分10
10秒前
贝贝完成签到 ,获得积分10
10秒前
11秒前
似水流年完成签到,获得积分10
11秒前
高贵的书包完成签到,获得积分10
11秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Single Cell Analysis of the Tumor Microenvironment Landscape Across the Disease Spectrum of Multiple Myeloma 1000
2026年中国辛酸癸酸聚乙二醇甘油酯行业市场现状调查及投资机会研判报告 1000
2026年中国辛酸癸酸聚乙二醇甘油酯行业市场规模及竞争格局分析报告 1000
模型平均及其应用 900
Fundamentals of Pharmaceutical and Biologics Regulations: A Global Perspective, Second Edition 700
The Cambridge History of China 英文版16册 600
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7332036
求助须知:如何正确求助?哪些是违规求助? 8946508
关于积分的说明 18977872
捐赠科研通 6986246
什么是DOI,文献DOI怎么找? 3216910
关于科研通互助平台的介绍 2383453
邀请新用户注册赠送积分活动 2196604