Sentinel: An Aggregation Function to Secure Decentralized Federated Learning

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Feng, Chao, Celdrán, Alberto Huertas, Baltensperger, Janosch, Beltrán, Enrique Tomás Martínez, Sánchez, Pedro Miguel Sánchez, Bovet, Gérôme, Stiller, Burkhard
Format: Preprint
Veröffentlicht: 2023
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866916381299048448
author Feng, Chao
Celdrán, Alberto Huertas
Baltensperger, Janosch
Beltrán, Enrique Tomás Martínez
Sánchez, Pedro Miguel Sánchez
Bovet, Gérôme
Stiller, Burkhard
author_facet Feng, Chao
Celdrán, Alberto Huertas
Baltensperger, Janosch
Beltrán, Enrique Tomás Martínez
Sánchez, Pedro Miguel Sánchez
Bovet, Gérôme
Stiller, Burkhard
contents Decentralized Federated Learning (DFL) emerges as an innovative paradigm to train collaborative models, addressing the single point of failure limitation. However, the security and trustworthiness of FL and DFL are compromised by poisoning attacks, negatively impacting its performance. Existing defense mechanisms have been designed for centralized FL and they do not adequately exploit the particularities of DFL. Thus, this work introduces Sentinel, a defense strategy to counteract poisoning attacks in DFL. Sentinel leverages the accessibility of local data and defines a three-step aggregation protocol consisting of similarity filtering, bootstrap validation, and normalization to safeguard against malicious model updates. Sentinel has been evaluated with diverse datasets and data distributions. Besides, various poisoning attack types and threat levels have been verified. The results improve the state-of-the-art performance against both untargeted and targeted poisoning attacks when data follows an IID (Independent and Identically Distributed) configuration. Besides, under non-IID configuration, it is analyzed how performance degrades both for Sentinel and other state-of-the-art robust aggregation methods.
format Preprint
id arxiv_https___arxiv_org_abs_2310_08097
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Sentinel: An Aggregation Function to Secure Decentralized Federated Learning
Feng, Chao
Celdrán, Alberto Huertas
Baltensperger, Janosch
Beltrán, Enrique Tomás Martínez
Sánchez, Pedro Miguel Sánchez
Bovet, Gérôme
Stiller, Burkhard
Distributed, Parallel, and Cluster Computing
Artificial Intelligence
Decentralized Federated Learning (DFL) emerges as an innovative paradigm to train collaborative models, addressing the single point of failure limitation. However, the security and trustworthiness of FL and DFL are compromised by poisoning attacks, negatively impacting its performance. Existing defense mechanisms have been designed for centralized FL and they do not adequately exploit the particularities of DFL. Thus, this work introduces Sentinel, a defense strategy to counteract poisoning attacks in DFL. Sentinel leverages the accessibility of local data and defines a three-step aggregation protocol consisting of similarity filtering, bootstrap validation, and normalization to safeguard against malicious model updates. Sentinel has been evaluated with diverse datasets and data distributions. Besides, various poisoning attack types and threat levels have been verified. The results improve the state-of-the-art performance against both untargeted and targeted poisoning attacks when data follows an IID (Independent and Identically Distributed) configuration. Besides, under non-IID configuration, it is analyzed how performance degrades both for Sentinel and other state-of-the-art robust aggregation methods.
title Sentinel: An Aggregation Function to Secure Decentralized Federated Learning
topic Distributed, Parallel, and Cluster Computing
Artificial Intelligence
url https://arxiv.org/abs/2310.08097