SureFED: Robust Federated Learning via Uncertainty-Aware Inward and Outward Inspection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Heydaribeni, Nasimeh, Zhang, Ruisi, Javidi, Tara, Nita-Rotaru, Cristina, Koushanfar, Farinaz
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913248602750976
author Heydaribeni, Nasimeh
Zhang, Ruisi
Javidi, Tara
Nita-Rotaru, Cristina
Koushanfar, Farinaz
author_facet Heydaribeni, Nasimeh
Zhang, Ruisi
Javidi, Tara
Nita-Rotaru, Cristina
Koushanfar, Farinaz
contents In this work, we introduce SureFED, a novel framework for byzantine robust federated learning. Unlike many existing defense methods that rely on statistically robust quantities, making them vulnerable to stealthy and colluding attacks, SureFED establishes trust using the local information of benign clients. SureFED utilizes an uncertainty aware model evaluation and introspection to safeguard against poisoning attacks. In particular, each client independently trains a clean local model exclusively using its local dataset, acting as the reference point for evaluating model updates. SureFED leverages Bayesian models that provide model uncertainties and play a crucial role in the model evaluation process. Our framework exhibits robustness even when the majority of clients are compromised, remains agnostic to the number of malicious clients, and is well-suited for non-IID settings. We theoretically prove the robustness of our algorithm against data and model poisoning attacks in a decentralized linear regression setting. Proof-of Concept evaluations on benchmark image classification data demonstrate the superiority of SureFED over the state of the art defense methods under various colluding and non-colluding data and model poisoning attacks.
format Preprint
id arxiv_https___arxiv_org_abs_2308_02747
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle SureFED: Robust Federated Learning via Uncertainty-Aware Inward and Outward Inspection
Heydaribeni, Nasimeh
Zhang, Ruisi
Javidi, Tara
Nita-Rotaru, Cristina
Koushanfar, Farinaz
Machine Learning
Distributed, Parallel, and Cluster Computing
Multiagent Systems
In this work, we introduce SureFED, a novel framework for byzantine robust federated learning. Unlike many existing defense methods that rely on statistically robust quantities, making them vulnerable to stealthy and colluding attacks, SureFED establishes trust using the local information of benign clients. SureFED utilizes an uncertainty aware model evaluation and introspection to safeguard against poisoning attacks. In particular, each client independently trains a clean local model exclusively using its local dataset, acting as the reference point for evaluating model updates. SureFED leverages Bayesian models that provide model uncertainties and play a crucial role in the model evaluation process. Our framework exhibits robustness even when the majority of clients are compromised, remains agnostic to the number of malicious clients, and is well-suited for non-IID settings. We theoretically prove the robustness of our algorithm against data and model poisoning attacks in a decentralized linear regression setting. Proof-of Concept evaluations on benchmark image classification data demonstrate the superiority of SureFED over the state of the art defense methods under various colluding and non-colluding data and model poisoning attacks.
title SureFED: Robust Federated Learning via Uncertainty-Aware Inward and Outward Inspection
topic Machine Learning
Distributed, Parallel, and Cluster Computing
Multiagent Systems
url https://arxiv.org/abs/2308.02747