Certifiably-Robust Federated Adversarial Learning via Randomized Smoothing

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Chen, Cheng, Kailkhura, Bhavya, Goldhahn, Ryan, Zhou, Yi
Format: Preprint
Published: 2021
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914698514923520
author Chen, Cheng
Kailkhura, Bhavya
Goldhahn, Ryan
Zhou, Yi
author_facet Chen, Cheng
Kailkhura, Bhavya
Goldhahn, Ryan
Zhou, Yi
contents Federated learning is an emerging data-private distributed learning framework, which, however, is vulnerable to adversarial attacks. Although several heuristic defenses are proposed to enhance the robustness of federated learning, they do not provide certifiable robustness guarantees. In this paper, we incorporate randomized smoothing techniques into federated adversarial training to enable data-private distributed learning with certifiable robustness to test-time adversarial perturbations. Our experiments show that such an advanced federated adversarial learning framework can deliver models as robust as those trained by the centralized training. Further, this enables provably-robust classifiers to $\ell_2$-bounded adversarial perturbations in a distributed setup. We also show that one-point gradient estimation based training approach is $2-3\times$ faster than popular stochastic estimator based approach without any noticeable certified robustness differences.
format Preprint
id arxiv_https___arxiv_org_abs_2103_16031
institution arXiv
publishDate 2021
record_format arxiv
spellingShingle Certifiably-Robust Federated Adversarial Learning via Randomized Smoothing
Chen, Cheng
Kailkhura, Bhavya
Goldhahn, Ryan
Zhou, Yi
Machine Learning
Federated learning is an emerging data-private distributed learning framework, which, however, is vulnerable to adversarial attacks. Although several heuristic defenses are proposed to enhance the robustness of federated learning, they do not provide certifiable robustness guarantees. In this paper, we incorporate randomized smoothing techniques into federated adversarial training to enable data-private distributed learning with certifiable robustness to test-time adversarial perturbations. Our experiments show that such an advanced federated adversarial learning framework can deliver models as robust as those trained by the centralized training. Further, this enables provably-robust classifiers to $\ell_2$-bounded adversarial perturbations in a distributed setup. We also show that one-point gradient estimation based training approach is $2-3\times$ faster than popular stochastic estimator based approach without any noticeable certified robustness differences.
title Certifiably-Robust Federated Adversarial Learning via Randomized Smoothing
topic Machine Learning
url https://arxiv.org/abs/2103.16031