FedRDF: A Robust and Dynamic Aggregation Function against Poisoning Attacks in Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Campos, Enrique Mármol, Vidal, Aurora González, Ramos, José Luis Hernández, Skarmeta, Antonio
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913235151618048
author Campos, Enrique Mármol
Vidal, Aurora González
Ramos, José Luis Hernández
Skarmeta, Antonio
author_facet Campos, Enrique Mármol
Vidal, Aurora González
Ramos, José Luis Hernández
Skarmeta, Antonio
contents Federated Learning (FL) represents a promising approach to typical privacy concerns associated with centralized Machine Learning (ML) deployments. Despite its well-known advantages, FL is vulnerable to security attacks such as Byzantine behaviors and poisoning attacks, which can significantly degrade model performance and hinder convergence. The effectiveness of existing approaches to mitigate complex attacks, such as median, trimmed mean, or Krum aggregation functions, has been only partially demonstrated in the case of specific attacks. Our study introduces a novel robust aggregation mechanism utilizing the Fourier Transform (FT), which is able to effectively handling sophisticated attacks without prior knowledge of the number of attackers. Employing this data technique, weights generated by FL clients are projected into the frequency domain to ascertain their density function, selecting the one exhibiting the highest frequency. Consequently, malicious clients' weights are excluded. Our proposed approach was tested against various model poisoning attacks, demonstrating superior performance over state-of-the-art aggregation methods.
format Preprint
id arxiv_https___arxiv_org_abs_2402_10082
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle FedRDF: A Robust and Dynamic Aggregation Function against Poisoning Attacks in Federated Learning
Campos, Enrique Mármol
Vidal, Aurora González
Ramos, José Luis Hernández
Skarmeta, Antonio
Machine Learning
Cryptography and Security
Federated Learning (FL) represents a promising approach to typical privacy concerns associated with centralized Machine Learning (ML) deployments. Despite its well-known advantages, FL is vulnerable to security attacks such as Byzantine behaviors and poisoning attacks, which can significantly degrade model performance and hinder convergence. The effectiveness of existing approaches to mitigate complex attacks, such as median, trimmed mean, or Krum aggregation functions, has been only partially demonstrated in the case of specific attacks. Our study introduces a novel robust aggregation mechanism utilizing the Fourier Transform (FT), which is able to effectively handling sophisticated attacks without prior knowledge of the number of attackers. Employing this data technique, weights generated by FL clients are projected into the frequency domain to ascertain their density function, selecting the one exhibiting the highest frequency. Consequently, malicious clients' weights are excluded. Our proposed approach was tested against various model poisoning attacks, demonstrating superior performance over state-of-the-art aggregation methods.
title FedRDF: A Robust and Dynamic Aggregation Function against Poisoning Attacks in Federated Learning
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2402.10082