FedGT: Identification of Malicious Clients in Federated Learning with Secure Aggregation

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Xhemrishi, Marvin, Östman, Johan, Wachter-Zeh, Antonia, Amat, Alexandre Graell i
Format: Preprint
Publié: 2023
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866917716881833984
author Xhemrishi, Marvin
Östman, Johan
Wachter-Zeh, Antonia
Amat, Alexandre Graell i
author_facet Xhemrishi, Marvin
Östman, Johan
Wachter-Zeh, Antonia
Amat, Alexandre Graell i
contents We propose FedGT, a novel framework for identifying malicious clients in federated learning with secure aggregation. Inspired by group testing, the framework leverages overlapping groups of clients to identify the presence of malicious clients in the groups via a decoding operation. The clients identified as malicious are then removed from the model training, which is performed over the remaining clients. By choosing the size, number, and overlap between groups, FedGT strikes a balance between privacy and security. Specifically, the server learns the aggregated model of the clients in each group - vanilla federated learning and secure aggregation correspond to the extreme cases of FedGT with group size equal to one and the total number of clients, respectively. The effectiveness of FedGT is demonstrated through extensive experiments on the MNIST, CIFAR-10, and ISIC2019 datasets in a cross-silo setting under different data-poisoning attacks. These experiments showcase FedGT's ability to identify malicious clients, resulting in high model utility. We further show that FedGT significantly outperforms the private robust aggregation approach based on the geometric median recently proposed by Pillutla et al. in multiple settings.
format Preprint
id arxiv_https___arxiv_org_abs_2305_05506
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle FedGT: Identification of Malicious Clients in Federated Learning with Secure Aggregation
Xhemrishi, Marvin
Östman, Johan
Wachter-Zeh, Antonia
Amat, Alexandre Graell i
Machine Learning
Cryptography and Security
Information Theory
We propose FedGT, a novel framework for identifying malicious clients in federated learning with secure aggregation. Inspired by group testing, the framework leverages overlapping groups of clients to identify the presence of malicious clients in the groups via a decoding operation. The clients identified as malicious are then removed from the model training, which is performed over the remaining clients. By choosing the size, number, and overlap between groups, FedGT strikes a balance between privacy and security. Specifically, the server learns the aggregated model of the clients in each group - vanilla federated learning and secure aggregation correspond to the extreme cases of FedGT with group size equal to one and the total number of clients, respectively. The effectiveness of FedGT is demonstrated through extensive experiments on the MNIST, CIFAR-10, and ISIC2019 datasets in a cross-silo setting under different data-poisoning attacks. These experiments showcase FedGT's ability to identify malicious clients, resulting in high model utility. We further show that FedGT significantly outperforms the private robust aggregation approach based on the geometric median recently proposed by Pillutla et al. in multiple settings.
title FedGT: Identification of Malicious Clients in Federated Learning with Secure Aggregation
topic Machine Learning
Cryptography and Security
Information Theory
url https://arxiv.org/abs/2305.05506