MUD-PQFed: Towards Malicious User Detection on model corruption in Privacy-preserving Quantized Federated learning

Date

2023

Authors

Ma, H.
Li, Q.
Zheng, Y.
Zhang, Z.
Liu, X.
Gao, Y.
Al-Sarawi, S.F.
Abbott, D.

Editors

Advisors

Journal Title

Journal ISSN

Volume Title

Type:

Journal article

Citation

Computers and Security, 2023; 133:103406-1-103406-15

Statement of Responsibility

Hua Ma, Qun Li, Yifeng Zheng, Zhi Zhang, Xiaoning Liu, Yansong Gao, Said F. Al-Sarawi, Derek Abbott

Conference Name

Abstract

The use of cryptographic privacy-preserving techniques in Federated Learning (FL) inadvertently induces a security dilemma because tampered local model parameters are encrypted and thus prevented from auditing. This work firstly demonstrates the triviality of performing model corruption attacks against privacy-preserving FL. We consider the scenario where the model updates are quantized to reduce the communication overhead, whilst the adversary can simply provide local parameters out of a legitimate range to corrupt the model. We then propose MUD-PQFed, a protocol that can precisely detect malicious attacks and enforce fair penalties on malicious clients. By deleting the contributions from the detected malicious clients, the global model utility is preserved as compared to the baseline global model in the absence of the corruption attack. Extensive experiments on MNIST, CIFAR-10, and CelebA benchmark datasets validate the efficacy in terms of retaining the baseline accuracy and effectiveness in terms of detecting malicious clients in a fine-grained manner.

School/Discipline

Dissertation Note

Provenance

Description

Access Status

Rights

© 2023 Elsevier Ltd. All rights reserved.

License

Call number

Persistent link to this record