SAFELearning: Enable Backdoor Detectability In Federated Learning With Secure Aggregation

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Zhang, Zhuosheng, Li, Jiarui, Yu, Shucheng, Makaya, Christian
Format: Preprint
Veröffentlicht: 2021
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866909180592390144
author Zhang, Zhuosheng
Li, Jiarui
Yu, Shucheng
Makaya, Christian
author_facet Zhang, Zhuosheng
Li, Jiarui
Yu, Shucheng
Makaya, Christian
contents For model privacy, local model parameters in federated learning shall be obfuscated before sent to the remote aggregator. This technique is referred to as \emph{secure aggregation}. However, secure aggregation makes model poisoning attacks such backdooring more convenient considering that existing anomaly detection methods mostly require access to plaintext local models. This paper proposes SAFELearning which supports backdoor detection for secure aggregation. We achieve this through two new primitives - \emph{oblivious random grouping (ORG)} and \emph{partial parameter disclosure (PPD)}. ORG partitions participants into one-time random subgroups with group configurations oblivious to participants; PPD allows secure partial disclosure of aggregated subgroup models for anomaly detection without leaking individual model privacy. SAFELearning can significantly reduce backdoor model accuracy without jeopardizing the main task accuracy under common backdoor strategies. Extensive experiments show SAFELearning is robust against malicious and faulty participants, whilst being more efficient than the state-of-art secure aggregation protocol in terms of both communication and computation costs.
format Preprint
id arxiv_https___arxiv_org_abs_2102_02402
institution arXiv
publishDate 2021
record_format arxiv
spellingShingle SAFELearning: Enable Backdoor Detectability In Federated Learning With Secure Aggregation
Zhang, Zhuosheng
Li, Jiarui
Yu, Shucheng
Makaya, Christian
Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
68M25 (Primary), 68T01 (Secondary)
C.2.4; I.2.11
For model privacy, local model parameters in federated learning shall be obfuscated before sent to the remote aggregator. This technique is referred to as \emph{secure aggregation}. However, secure aggregation makes model poisoning attacks such backdooring more convenient considering that existing anomaly detection methods mostly require access to plaintext local models. This paper proposes SAFELearning which supports backdoor detection for secure aggregation. We achieve this through two new primitives - \emph{oblivious random grouping (ORG)} and \emph{partial parameter disclosure (PPD)}. ORG partitions participants into one-time random subgroups with group configurations oblivious to participants; PPD allows secure partial disclosure of aggregated subgroup models for anomaly detection without leaking individual model privacy. SAFELearning can significantly reduce backdoor model accuracy without jeopardizing the main task accuracy under common backdoor strategies. Extensive experiments show SAFELearning is robust against malicious and faulty participants, whilst being more efficient than the state-of-art secure aggregation protocol in terms of both communication and computation costs.
title SAFELearning: Enable Backdoor Detectability In Federated Learning With Secure Aggregation
topic Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
68M25 (Primary), 68T01 (Secondary)
C.2.4; I.2.11
url https://arxiv.org/abs/2102.02402