Journal article
Defending against data poisoning attacks: from distributed learning to federated learning
- Abstract:
- Federated learning (FL), a variant of distributed learning (DL), supports the training of a shared model without accessing private data from different sources. Despite its benefits with regard to privacy preservation, FL’s distributed nature and privacy constraints make it vulnerable to data poisoning attacks. Existing defenses, primarily designed for DL, are typically not well adapted to FL. In this paper, we study such attacks and defenses. In doing so, we start from the perspective of DL and then give consideration to a real-world FL scenario, with the aim being to explore the requisites of a desirable defense in FL. Our study shows that (i) the batch size used in each training round affects the effectiveness of defenses in DL, (ii) the defenses investigated are somewhat effective and moderately influenced by batch size in FL settings and (iii) the non-IID data makes it more difficult to defend against data poisoning attacks in FL. Based on the findings, we discuss the key challenges and possible directions in defending against such attacks in FL. In addition, we propose detect and suppress the potential outliers(DSPO), a defense against data poisoning attacks in FL scenarios. Our results show that DSPO outperforms other defenses in several cases.
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Access Document
- Files:
-
-
(Preview, Accepted manuscript, pdf, 691.0KB, Terms of use)
-
- Publisher copy:
- 10.1093/comjnl/bxab192
Authors
- Publisher:
- Oxford University Press
- Journal:
- The Computer Journal More from this journal
- Volume:
- 66
- Issue:
- 3
- Pages:
- 711-726
- Publication date:
- 2021-12-18
- Acceptance date:
- 2021-11-04
- DOI:
- EISSN:
-
1460-2067
- ISSN:
-
0010-4620
- Language:
-
English
- Keywords:
- Pubs id:
-
1207456
- Local pid:
-
pubs:1207456
- Deposit date:
-
2021-11-05
- ARK identifier:
Terms of use
- Copyright holder:
- Tian et al.
- Copyright date:
- 2021
- Rights statement:
- © The Author(s) 2021. Published by Oxford University Press on behalf of The British Computer Society. All rights reserved.
- Notes:
- This is the accepted manuscript version of the article. The final version is available online from Oxford University Press at: https://doi.org/10.1093/comjnl/bxab192
If you are the owner of this record, you can report an update to it here: Report update to this record