pFedDef: Defending Grey-Box Attacks for Personalized Federated Learning

09/17/2022
by   Taejin Kim, et al.
0

Personalized federated learning allows for clients in a distributed system to train a neural network tailored to their unique local data while leveraging information at other clients. However, clients' models are vulnerable to attacks during both the training and testing phases. In this paper we address the issue of adversarial clients crafting evasion attacks at test time to deceive other clients. For example, adversaries may aim to deceive spam filters and recommendation systems trained with personalized federated learning for monetary gain. The adversarial clients have varying degrees of personalization based on the method of distributed learning, leading to a "grey-box" situation. We are the first to characterize the transferability of such internal evasion attacks for different learning methods and analyze the trade-off between model accuracy and robustness depending on the degree of personalization and similarities in client data. We introduce a defense mechanism, pFedDef, that performs personalized federated adversarial training while respecting resource limitations at clients that inhibit adversarial training. Overall, pFedDef increases relative grey-box adversarial robustness by 62 adversarial training and performs well even under limited system resources.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/18/2022

PerFED-GAN: Personalized Federated Learning via Generative Adversarial Networks

Federated learning is gaining popularity as a distributed machine learni...
research
10/26/2021

Ensemble Federated Adversarial Training with Non-IID data

Despite federated learning endows distributed clients with a cooperative...
research
03/01/2023

Combating Exacerbated Heterogeneity for Robust Models in Federated Learning

Privacy and security concerns in real-world applications have led to the...
research
03/02/2022

Personalized Federated Learning With Structure

Knowledge sharing and model personalization are two key components to im...
research
10/15/2021

FedMe: Federated Learning via Model Exchange

Federated learning is a distributed machine learning method in which a s...
research
08/24/2023

A Huber Loss Minimization Approach to Byzantine Robust Federated Learning

Federated learning systems are susceptible to adversarial attacks. To co...
research
01/18/2022

Model Transferring Attacks to Backdoor HyperNetwork in Personalized Federated Learning

This paper explores previously unknown backdoor risks in HyperNet-based ...

Please sign up or login with your details

Forgot password? Click here to reset