PEAR: privacy-preserving and effective aggregation for byzantine-robust federated learning in real-world scenarios

计算机科学 联合学习 拜占庭式建筑 计算机安全 互联网隐私 人工智能 万维网 地理 考古
作者
Han Sun,Yan Zhang,Huiping Zhuang,Jiatong Li,Zhi Xu,Liji Wu
出处
期刊:The Computer Journal [Oxford University Press]
被引量:2
标识
DOI:10.1093/comjnl/bxae086
摘要

Abstract Federated learning (FL) enables collaborative training of global models among distributed clients without sharing local data. Secure aggregation, a new security primitive of FL, enhances the confidentiality of data and model parameters. Unfortunately, privacy-preserving (PP) FL is vulnerable to common poisoning attacks by Byzantine adversaries. Existing defense strategies mainly focus on identifying abnormal local gradients over plaintexts, which provides a weak privacy guarantee. In PPFL, adversaries can escape existing defenses by uploading encrypted poisonous gradients. In addition, most mainstream aggregation algorithms assume that clients’ local training data is uniformly distributed, Independent and Identically Distributed (IID), which is unrealistic for real-world FL scenarios where data are only stored on large-scale terminal devices. To address these issues, we propose PEAR, a PP aggregation strategy based on single key-dual server CKKS full homomorphic encryption in real-world distributed scenarios, which can resist encrypted poisoning attacks. Specifically, we use cosine similarity to measure the distance between encrypted gradients. Then, we propose a novel Byzantine-tolerance aggregation mechanism using cosine similarity, which includes trust score generation that can tolerate differentiated local gradients and a two-step weight generation method that considers both the degree of gradient deviation in direction and training data size. This mechanism can achieve robustness for both IID and non-IID data without compromising privacy. Our extensive evaluations for two typical poisoning attacks on different datasets show that PEAR is robust and effective in IID and non-IID data and outperforms existing mainstream Byzantine-robust algorithms, especially achieving 16.4% to 53.2% testing error rate reduction in non-IID settings with significant label distribution and quantity skew while maintaining the same efficiency as FedAvg.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
刚刚
1秒前
情怀应助淇淇采纳,获得30
2秒前
科研通AI6.4应助Daleth采纳,获得10
3秒前
芙芙发布了新的文献求助20
3秒前
4秒前
Ella完成签到,获得积分10
4秒前
4秒前
4秒前
llll发布了新的文献求助10
5秒前
5秒前
5秒前
6秒前
7秒前
7秒前
禾梦发布了新的文献求助10
7秒前
clwlf发布了新的文献求助10
7秒前
科目三应助Ivy采纳,获得10
8秒前
拼搏的梦凡完成签到,获得积分10
9秒前
10秒前
热闹的冬天完成签到,获得积分10
11秒前
任伟超发布了新的文献求助10
11秒前
啊娴子发布了新的文献求助10
11秒前
12秒前
Amazong发布了新的文献求助10
12秒前
llll发布了新的文献求助10
12秒前
英俊的铭应助乐爱来采纳,获得30
14秒前
15秒前
小剧场发布了新的文献求助10
15秒前
科研通AI6.4应助淇淇采纳,获得10
15秒前
17秒前
17秒前
yyyyyyyyy完成签到,获得积分10
17秒前
叶子完成签到,获得积分10
18秒前
刘可乐完成签到,获得积分10
18秒前
Chen完成签到,获得积分10
19秒前
科研通AI6.2应助zxc采纳,获得30
20秒前
21秒前
hzc完成签到,获得积分10
21秒前
21秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
Reducing Compassion Fatigue, Secondary Traumatic Stress and Burnout 600
China Pluperfect I: Epistemology of Past and Outside in Chinese Art 520
Matrix Methods in Data Mining and Pattern Recognition Second Edition 510
Mammalian Synthetic Biology 500
Auslegungsgeschichte 500
Cosmos as Art Object: Studies in Plato's Timaeus and Other Dialogues 500
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 内科学 物理 复合材料 催化作用 细胞生物学 无机化学 光电子学 物理化学 电极 基因
热门帖子
关注 科研通微信公众号,转发送积分 7638903
求助须知:如何正确求助?哪些是违规求助? 9212111
关于积分的说明 19761166
捐赠科研通 7205811
什么是DOI,文献DOI怎么找? 3275906
关于科研通互助平台的介绍 2437495
邀请新用户注册赠送积分活动 2273206