SHERPA: Explainable Robust Algorithms for Privacy-Preserved Federated Learning in Future Networks to Defend Against Data Poisoning Attacks
Chamara Sandeepa, Bartlomiej Siniarski, Shen Wang, Madhusanka Liyanage
摘要
With the rapid progression of communication and localisation of big data over billions of devices, distributed Machine Learning (ML) techniques are emerging to cater for the development of Artificial Intelligence (AI)-based services in a distributed manner. Federated Learning (FL) is such an innovative approach to achieve a privacy-preserved AI that facilitates ML model sharing and aggregation while keeping the participants’ data at the original source. However, recent research has investigated threats from poisoning attacks in FL. Several robust algorithms based on techniques such as similarity metrics or anomaly filtering are proposed as solutions. Yet, these approaches do not focus on investigating the intentions of the attackers or providing justifications and evidence for suspecting the behaviour of clients who are considered poisoners. Therefore, we propose SHERPA, a robust algorithm that uses Shapley Additive Explanations (SHAP) to identify potential poisoners in an FL system. Based on this, we develop a novel algorithm to differentiate poisoners via feature attribution clustering. We launch data poisoning attacks for different scenarios on multiple datasets and showcase our solution to mitigate the attacks. Furthermore, we show that privacy-targeted poisoning attacks can be mitigated with our approach. Accompanying the Explainable AI (XAI) technique for defence, our study reveals the potential for post-hoc feature attributions in countering data poisoning attacks with better explainability and improved justification in eliminating potentially malicious clients in the aggregation process.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper5
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 被引用 1,736 次
- Evaluating Gradient Inversion Attacks and Defenses in Federated LearningYangsibo Huang, Samyak Gupta, Zhao Song, Kai Li 等NeurIPS 2021 · 被引用 419 次
- FLAME: Taming Backdoors in Federated LearningThien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame 等USENIX Security 2022
- FLTrust: Byzantine-robust Federated Learning via Trust BootstrappingXiaoyu Cao, Minghong Fang, Jia Liu, Neil Zhenqiang GongNDSS 2021
相关 Paper
- Find a Scapegoat: Poisoning Membership Inference Attack and Defense to Federated LearningWenjin Mo, Zhiyuan Li, Minghong Fang, Mingwei FangICCV 2025 · 被引用 3 次
- Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated LearningVirat Shejwalkar, Amir HoumansadrNDSS 2021
- FedXDS: Leveraging Model Attribution Methods to Counteract Data Heterogeneity in Federated LearningMaximilian Andreas Hoefler, Karsten Müller, Wojciech SamekICCV 2025
- RFLPA: A Robust Federated Learning Framework against Poisoning Attacks with Secure AggregationPeihua Mai, Ran Yan, Yan PangNeurIPS 2024 · 被引用 51 次
- ACE: A Model Poisoning Attack on Contribution Evaluation Methods in Federated LearningZhangchen Xu, Fengqing Jiang, Luyao Niu, Jinyuan Jia 等USENIX Security 2024 · 被引用 11 次
