Securing Federated Sensitive Topic Classification against Poisoning Attacks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Chu, Tianyue, Garcia-Recuero, Alvaro, Iordanou, Costas, Smaragdakis, Georgios, Laoutaris, Nikolaos
Natura: Preprint
Pubblicazione: 2022
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866910400335839232
author Chu, Tianyue
Garcia-Recuero, Alvaro
Iordanou, Costas
Smaragdakis, Georgios
Laoutaris, Nikolaos
author_facet Chu, Tianyue
Garcia-Recuero, Alvaro
Iordanou, Costas
Smaragdakis, Georgios
Laoutaris, Nikolaos
contents We present a Federated Learning (FL) based solution for building a distributed classifier capable of detecting URLs containing GDPR-sensitive content related to categories such as health, sexual preference, political beliefs, etc. Although such a classifier addresses the limitations of previous offline/centralised classifiers,it is still vulnerable to poisoning attacks from malicious users that may attempt to reduce the accuracy for benign users by disseminating faulty model updates. To guard against this, we develop a robust aggregation scheme based on subjective logic and residual-based attack detection. Employing a combination of theoretical analysis, trace-driven simulation, as well as experimental validation with a prototype and real users, we show that our classifier can detect sensitive content with high accuracy, learn new labels fast, and remain robust in view of poisoning attacks from malicious users, as well as imperfect input from non-malicious ones.
format Preprint
id arxiv_https___arxiv_org_abs_2201_13086
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle Securing Federated Sensitive Topic Classification against Poisoning Attacks
Chu, Tianyue
Garcia-Recuero, Alvaro
Iordanou, Costas
Smaragdakis, Georgios
Laoutaris, Nikolaos
Cryptography and Security
Distributed, Parallel, and Cluster Computing
68M25
I.2.11; K.4.1
We present a Federated Learning (FL) based solution for building a distributed classifier capable of detecting URLs containing GDPR-sensitive content related to categories such as health, sexual preference, political beliefs, etc. Although such a classifier addresses the limitations of previous offline/centralised classifiers,it is still vulnerable to poisoning attacks from malicious users that may attempt to reduce the accuracy for benign users by disseminating faulty model updates. To guard against this, we develop a robust aggregation scheme based on subjective logic and residual-based attack detection. Employing a combination of theoretical analysis, trace-driven simulation, as well as experimental validation with a prototype and real users, we show that our classifier can detect sensitive content with high accuracy, learn new labels fast, and remain robust in view of poisoning attacks from malicious users, as well as imperfect input from non-malicious ones.
title Securing Federated Sensitive Topic Classification against Poisoning Attacks
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
68M25
I.2.11; K.4.1
url https://arxiv.org/abs/2201.13086