MUD-PQFed: Towards Malicious User Detection on model corruption in Privacy-preserving Quantized Federated learning
Date
2023
Authors
Ma, H.
Li, Q.
Zheng, Y.
Zhang, Z.
Liu, X.
Gao, Y.
Al-Sarawi, S.F.
Abbott, D.
Editors
Advisors
Journal Title
Journal ISSN
Volume Title
Type:
Journal article
Citation
Computers and Security, 2023; 133:103406-1-103406-15
Statement of Responsibility
Hua Ma, Qun Li, Yifeng Zheng, Zhi Zhang, Xiaoning Liu, Yansong Gao, Said F. Al-Sarawi, Derek Abbott
Conference Name
Abstract
The use of cryptographic privacy-preserving techniques in Federated Learning (FL) inadvertently induces a security dilemma because tampered local model parameters are encrypted and thus prevented from auditing. This work firstly demonstrates the triviality of performing model corruption attacks against privacy-preserving FL. We consider the scenario where the model updates are quantized to reduce the communication overhead, whilst the adversary can simply provide local parameters out of a legitimate range to corrupt the model. We then propose MUD-PQFed, a protocol that can precisely detect malicious attacks and enforce fair penalties on malicious clients. By deleting the contributions from the detected malicious clients, the global model utility is preserved as compared to the baseline global model in the absence of the corruption attack. Extensive experiments on MNIST, CIFAR-10, and CelebA benchmark datasets validate the efficacy in terms of retaining the baseline accuracy and effectiveness in terms of detecting malicious clients in a fine-grained manner.
School/Discipline
Dissertation Note
Provenance
Description
Access Status
Rights
© 2023 Elsevier Ltd. All rights reserved.