FedAMM: Federated Learning Against Majority Malicious Clients Using Robust Aggregation

后门 计算机科学 判别式 计算机安全 聚类分析 数据挖掘 稳健性(进化) 方案(数学) 数据建模 稳健主成分分析 任务(项目管理) 过程(计算) 机器学习 恶意软件 人工智能 噪音(视频) 特洛伊木马 训练集 组分(热力学) 威胁模型 信息敏感性 黑名单 分类 信息隐私 直觉
作者
Keke Gai,Dongjue Wang,Jing Yu,Liehuang Zhu,Weizhi Meng
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:20: 9950-9964 被引量:1
标识
DOI:10.1109/tifs.2025.3607273
摘要

As a collaborative framework designed to safeguard privacy, Federated Learning (FL) seeks to protect participants’ data throughout the training process. However, the framework still faces security risks from poisoning attacks, arising from the unmonitored process of client-side model updates. Most existing solutions address scenarios where less than half of clients are malicious, i.e., which leaves a significant challenge to defend against attacks when more than half of participants are malicious. In this paper, we propose a FL scheme, named FedAMM, that resists backdoor attacks across various data distributions and malicious client ratios. We develop a novel backdoor defense mechanism to filter out malicious models, aiming to reduce the performance degradation of the model. The proposed scheme addresses the challenge of distance measurement in high-dimensional spaces by applying Principal Component Analysis (PCA) to improve clustering effectiveness. We borrow the idea of critical parameter analysis to enhance discriminative ability in non-iid data scenarios, via assessing the benign or malicious nature of models by comparing the similarity of critical parameters across different models. Finally, our scheme employs a hierarchical noise perturbation to improve the backdoor mitigation rate, effectively eliminating the backdoor and reducing the adverse effects of noise on task accuracy. Through evaluations conducted on multiple datasets, we demonstrate that the proposed scheme achieves superior backdoor defense across diverse client data distributions and different ratios of malicious participants. With 80% malicious clients, FedAMM achieves low backdoor attack success rates of 1.14%, 0.28%, and 5.53% on MNIST, FMNIST, and CIFAR-10, respectively, demonstrating enhanced robustness of FL against backdoor attacks.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
11111111111111完成签到,获得积分10
刚刚
拓跋寡妇发布了新的文献求助10
刚刚
阿莴鹅完成签到,获得积分10
刚刚
平常亦凝完成签到,获得积分10
刚刚
喜哥完成签到,获得积分10
刚刚
Flyzhang完成签到,获得积分10
刚刚
光亮若翠完成签到,获得积分10
刚刚
1秒前
ExtroGod完成签到,获得积分10
1秒前
孙兴燕完成签到,获得积分10
1秒前
青橙发布了新的文献求助10
1秒前
lq完成签到,获得积分10
2秒前
111完成签到,获得积分10
3秒前
俭朴迎荷完成签到,获得积分10
3秒前
今安完成签到,获得积分10
3秒前
BALL完成签到,获得积分10
3秒前
3秒前
ZCxiang完成签到,获得积分10
4秒前
feng完成签到,获得积分10
4秒前
科目三应助程若水采纳,获得10
4秒前
文南犬完成签到,获得积分10
4秒前
Akim应助俊杰采纳,获得10
5秒前
细心不评完成签到,获得积分10
5秒前
刘嘉乐完成签到,获得积分10
5秒前
开着飞机骑拖拉机完成签到,获得积分10
5秒前
MisterZhou完成签到,获得积分10
5秒前
jiangzhi完成签到,获得积分10
6秒前
MTN000发布了新的文献求助10
6秒前
6秒前
咿呀完成签到,获得积分10
7秒前
業業完成签到,获得积分10
7秒前
zyw发布了新的文献求助10
7秒前
今晚去吃烤肉完成签到,获得积分10
7秒前
7秒前
wrzymh完成签到 ,获得积分10
8秒前
带你去月球完成签到,获得积分10
8秒前
快发sci完成签到,获得积分10
8秒前
8秒前
cdercder应助文南犬采纳,获得10
8秒前
v0id应助唐唐88采纳,获得10
9秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Principles of town planning: translating concepts to applications 1000
Navigating Normative Orders. Interdisciplinary Perspectives 800
1 Peter and Christ's Descent to the Dead in Its Early Christian Reception 700
Organizational Behavior 510
Management and the Arts 510
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7739175
求助须知:如何正确求助?哪些是违规求助? 9288108
关于积分的说明 20187257
捐赠科研通 7317308
什么是DOI,文献DOI怎么找? 3306034
关于科研通互助平台的介绍 2458554
邀请新用户注册赠送积分活动 2315987