RFLPA: A Robust Federated Learning Framework against Poisoning Attacks with Secure Aggregation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Mai, Peihua, Yan, Ran, Pang, Yan
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909365959655424
author Mai, Peihua
Yan, Ran
Pang, Yan
author_facet Mai, Peihua
Yan, Ran
Pang, Yan
contents Federated learning (FL) allows multiple devices to train a model collaboratively without sharing their data. Despite its benefits, FL is vulnerable to privacy leakage and poisoning attacks. To address the privacy concern, secure aggregation (SecAgg) is often used to obtain the aggregation of gradients on sever without inspecting individual user updates. Unfortunately, existing defense strategies against poisoning attacks rely on the analysis of local updates in plaintext, making them incompatible with SecAgg. To reconcile the conflicts, we propose a robust federated learning framework against poisoning attacks (RFLPA) based on SecAgg protocol. Our framework computes the cosine similarity between local updates and server updates to conduct robust aggregation. Furthermore, we leverage verifiable packed Shamir secret sharing to achieve reduced communication cost of $O(M+N)$ per user, and design a novel dot product aggregation algorithm to resolve the issue of increased information leakage. Our experimental results show that RFLPA significantly reduces communication and computation overhead by over $75\%$ compared to the state-of-the-art secret sharing method, BREA, while maintaining competitive accuracy.
format Preprint
id arxiv_https___arxiv_org_abs_2405_15182
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle RFLPA: A Robust Federated Learning Framework against Poisoning Attacks with Secure Aggregation
Mai, Peihua
Yan, Ran
Pang, Yan
Cryptography and Security
Artificial Intelligence
E.4
Federated learning (FL) allows multiple devices to train a model collaboratively without sharing their data. Despite its benefits, FL is vulnerable to privacy leakage and poisoning attacks. To address the privacy concern, secure aggregation (SecAgg) is often used to obtain the aggregation of gradients on sever without inspecting individual user updates. Unfortunately, existing defense strategies against poisoning attacks rely on the analysis of local updates in plaintext, making them incompatible with SecAgg. To reconcile the conflicts, we propose a robust federated learning framework against poisoning attacks (RFLPA) based on SecAgg protocol. Our framework computes the cosine similarity between local updates and server updates to conduct robust aggregation. Furthermore, we leverage verifiable packed Shamir secret sharing to achieve reduced communication cost of $O(M+N)$ per user, and design a novel dot product aggregation algorithm to resolve the issue of increased information leakage. Our experimental results show that RFLPA significantly reduces communication and computation overhead by over $75\%$ compared to the state-of-the-art secret sharing method, BREA, while maintaining competitive accuracy.
title RFLPA: A Robust Federated Learning Framework against Poisoning Attacks with Secure Aggregation
topic Cryptography and Security
Artificial Intelligence
E.4
url https://arxiv.org/abs/2405.15182