Skip to main navigation Skip to search Skip to main content

Byzantine-robust Federated Learning through Collaborative Malicious Gradient Filtering

  • Jian Xu
  • , Shao-Lun Huang*
  • , Linqi Song
  • , Tian Lan
  • *Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Gradient-based training in federated learning is known to be vulnerable to faulty/malicious clients, which are often modeled as Byzantine clients. To this end, previous work either makes use of auxiliary data at parameter server to verify the received gradients (e.g., by computing validation error rate) or leverages statistic-based methods (e.g. median and Krum) to identify and remove malicious gradients from Byzantine clients. In this paper, we remark that auxiliary data may not always be available in practice and focus on the statistic-based approach. However, recent work on model poisoning attacks has shown that well-crafted attacks can circumvent most of median- and distance-based statistical defense methods, making malicious gradients indistinguishable from honest ones. To tackle this challenge, we show that the element-wise sign of gradient vector can provide valuable insight in detecting model poisoning attacks. Based on our theoretical analysis of the Little is Enough attack, we propose a novel approach called SignGuard to enable Byzantine-robust federated learning through collaborative malicious gradient filtering. More precisely, the received gradients are first processed to generate relevant magnitude, sign, and similarity statistics, which are then collaboratively utilized by multiple filters to eliminate malicious gradients before final aggregation. Finally, extensive experiments of image and text classification tasks are conducted under recently proposed attacks and defense strategies. The numerical results demonstrate the effectiveness and superiority of our proposed approach.
Original languageEnglish
Title of host publicationProceedings - 2022 IEEE 42nd International Conference on Distributed Computing Systems, ICDCS 2022
PublisherIEEE
Pages1223-1235
ISBN (Electronic)978-1-6654-7177-0
ISBN (Print)978-1-6654-7178-7
DOIs
Publication statusPublished - 2022
Event42nd IEEE International Conference on Distributed Computing Systems (ICDCS 2022) - Bologna, Italy
Duration: 10 Jul 202213 Jul 2022
https://icdcs2022.icdcs.org/

Publication series

NameProceedings - International Conference on Distributed Computing Systems
ISSN (Print)1063-6927
ISSN (Electronic)2575-8411

Conference

Conference42nd IEEE International Conference on Distributed Computing Systems (ICDCS 2022)
Abbreviated titleIEEE ICDCS 2022
PlaceItaly
CityBologna
Period10/07/2213/07/22
Internet address

Bibliographical note

Research Unit(s) information for this publication is provided by the author(s) concerned.

Funding

The research of Dr. Shao-Lun Huang is supported in part by the Shenzhen Science and Technology Program under Grant KQTD20170810150821146, National Key R&D Program of China under Grant 2021YFA0715202 and High-end Foreign Expert Talent Introduction Plan under Grant G2021032013L. The work of Dr. Linqi Song is supported in part by the Hong Kong RGC grant ECS 21212419, InnoHK initiative, the Government of the HKSAR, and Laboratory for AI-Powered Financial Technologies.

Research Keywords

  • Federated Learning
  • Attack Detection
  • Distributed Learning Security

RGC Funding Information

  • RGC-funded

Fingerprint

Dive into the research topics of 'Byzantine-robust Federated Learning through Collaborative Malicious Gradient Filtering'. Together they form a unique fingerprint.

Cite this