Tazza: Shuffling Neural Network Parameters for Secure and Private Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lee, Kichang, Jin, Jaeho, Park, JaeYeon, Kim, Songkuk, Ko, JeongGil
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908738875555840
author Lee, Kichang
Jin, Jaeho
Park, JaeYeon
Kim, Songkuk
Ko, JeongGil
author_facet Lee, Kichang
Jin, Jaeho
Park, JaeYeon
Kim, Songkuk
Ko, JeongGil
contents Federated learning enables decentralized model training without sharing raw data, preserving data privacy. However, its vulnerability towards critical security threats, such as gradient inversion and model poisoning by malicious clients, remain unresolved. Existing solutions often address these issues separately, sacrificing either system robustness or model accuracy. This work introduces Tazza, a secure and efficient federated learning framework that simultaneously addresses both challenges. By leveraging the permutation equivariance and invariance properties of neural networks via weight shuffling and shuffled model validation, Tazza enhances resilience against diverse poisoning attacks, while ensuring data confidentiality and high model accuracy. Comprehensive evaluations on various datasets and embedded platforms show that Tazza achieves robust defense with up to 6.7x improved computational efficiency compared to alternative schemes, without compromising performance.
format Preprint
id arxiv_https___arxiv_org_abs_2412_07454
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Tazza: Shuffling Neural Network Parameters for Secure and Private Federated Learning
Lee, Kichang
Jin, Jaeho
Park, JaeYeon
Kim, Songkuk
Ko, JeongGil
Machine Learning
Artificial Intelligence
68T07
I.2.11
Federated learning enables decentralized model training without sharing raw data, preserving data privacy. However, its vulnerability towards critical security threats, such as gradient inversion and model poisoning by malicious clients, remain unresolved. Existing solutions often address these issues separately, sacrificing either system robustness or model accuracy. This work introduces Tazza, a secure and efficient federated learning framework that simultaneously addresses both challenges. By leveraging the permutation equivariance and invariance properties of neural networks via weight shuffling and shuffled model validation, Tazza enhances resilience against diverse poisoning attacks, while ensuring data confidentiality and high model accuracy. Comprehensive evaluations on various datasets and embedded platforms show that Tazza achieves robust defense with up to 6.7x improved computational efficiency compared to alternative schemes, without compromising performance.
title Tazza: Shuffling Neural Network Parameters for Secure and Private Federated Learning
topic Machine Learning
Artificial Intelligence
68T07
I.2.11
url https://arxiv.org/abs/2412.07454