SignSGD with Federated Defense: Harnessing Adversarial Attacks through Gradient Sign Decoding

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Park, Chanho, Lee, Namyoon
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866910316556713984
author Park, Chanho
Lee, Namyoon
author_facet Park, Chanho
Lee, Namyoon
contents Distributed learning is an effective approach to accelerate model training using multiple workers. However, substantial communication delays emerge between workers and a parameter server due to massive costs associated with communicating gradients. SignSGD with majority voting (signSGD-MV) is a simple yet effective optimizer that reduces communication costs through one-bit quantization, yet the convergence rates considerably decrease as adversarial workers increase. In this paper, we show that the convergence rate is invariant as the number of adversarial workers increases, provided that the number of adversarial workers is smaller than that of benign workers. The key idea showing this counter-intuitive result is our novel signSGD with federated defense (signSGD-FD). Unlike the traditional approaches, signSGD-FD exploits the gradient information sent by adversarial workers with the proper weights, which are obtained through gradient sign decoding. Experimental results demonstrate signSGD-FD achieves superior convergence rates over traditional algorithms in various adversarial attack scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2402_01340
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle SignSGD with Federated Defense: Harnessing Adversarial Attacks through Gradient Sign Decoding
Park, Chanho
Lee, Namyoon
Machine Learning
Cryptography and Security
Signal Processing
Distributed learning is an effective approach to accelerate model training using multiple workers. However, substantial communication delays emerge between workers and a parameter server due to massive costs associated with communicating gradients. SignSGD with majority voting (signSGD-MV) is a simple yet effective optimizer that reduces communication costs through one-bit quantization, yet the convergence rates considerably decrease as adversarial workers increase. In this paper, we show that the convergence rate is invariant as the number of adversarial workers increases, provided that the number of adversarial workers is smaller than that of benign workers. The key idea showing this counter-intuitive result is our novel signSGD with federated defense (signSGD-FD). Unlike the traditional approaches, signSGD-FD exploits the gradient information sent by adversarial workers with the proper weights, which are obtained through gradient sign decoding. Experimental results demonstrate signSGD-FD achieves superior convergence rates over traditional algorithms in various adversarial attack scenarios.
title SignSGD with Federated Defense: Harnessing Adversarial Attacks through Gradient Sign Decoding
topic Machine Learning
Cryptography and Security
Signal Processing
url https://arxiv.org/abs/2402.01340