PPFPL: Cross-silo Privacy-preserving Federated Prototype Learning Against Data Poisoning Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Zhang, Hongliang, Yu, Jiguo, Xu, Fenghua, Hu, Chunqiang, Zhang, Yongzhao, Wang, Xiaofen, Yu, Zhongyuan, Zhang, Xiaosong
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908550866927616
author Zhang, Hongliang
Yu, Jiguo
Xu, Fenghua
Hu, Chunqiang
Zhang, Yongzhao
Wang, Xiaofen
Yu, Zhongyuan
Zhang, Xiaosong
author_facet Zhang, Hongliang
Yu, Jiguo
Xu, Fenghua
Hu, Chunqiang
Zhang, Yongzhao
Wang, Xiaofen
Yu, Zhongyuan
Zhang, Xiaosong
contents Privacy-Preserving Federated Learning (PPFL) enables multiple clients to collaboratively train models by submitting secreted model updates. Nonetheless, PPFL is vulnerable to data poisoning attacks due to its distributed training paradigm in cross-silo scenarios. Existing solutions have struggled to improve the performance of PPFL under poisoned Non-Independent and Identically Distributed (Non-IID) data. To address the issues, this paper proposes a privacy-preserving federated prototype learning framework, named PPFPL, which enhances the cross-silo FL performance against poisoned Non-IID data while protecting client privacy. Specifically, we adopt prototypes as client-submitted model updates to eliminate the impact of poisoned data distributions. In addition, we design a secure aggregation protocol utilizing homomorphic encryption to achieve Byzantine-robust aggregation on two servers, significantly reducing the impact of malicious clients. Theoretical analyses confirm the convergence and privacy of PPFPL. Experimental results on public datasets show that PPFPL effectively resists data poisoning attacks under Non-IID settings.
format Preprint
id arxiv_https___arxiv_org_abs_2504_03173
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle PPFPL: Cross-silo Privacy-preserving Federated Prototype Learning Against Data Poisoning Attacks
Zhang, Hongliang
Yu, Jiguo
Xu, Fenghua
Hu, Chunqiang
Zhang, Yongzhao
Wang, Xiaofen
Yu, Zhongyuan
Zhang, Xiaosong
Cryptography and Security
Distributed, Parallel, and Cluster Computing
Privacy-Preserving Federated Learning (PPFL) enables multiple clients to collaboratively train models by submitting secreted model updates. Nonetheless, PPFL is vulnerable to data poisoning attacks due to its distributed training paradigm in cross-silo scenarios. Existing solutions have struggled to improve the performance of PPFL under poisoned Non-Independent and Identically Distributed (Non-IID) data. To address the issues, this paper proposes a privacy-preserving federated prototype learning framework, named PPFPL, which enhances the cross-silo FL performance against poisoned Non-IID data while protecting client privacy. Specifically, we adopt prototypes as client-submitted model updates to eliminate the impact of poisoned data distributions. In addition, we design a secure aggregation protocol utilizing homomorphic encryption to achieve Byzantine-robust aggregation on two servers, significantly reducing the impact of malicious clients. Theoretical analyses confirm the convergence and privacy of PPFPL. Experimental results on public datasets show that PPFPL effectively resists data poisoning attacks under Non-IID settings.
title PPFPL: Cross-silo Privacy-preserving Federated Prototype Learning Against Data Poisoning Attacks
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2504.03173