DeFL: Defending against Model Poisoning Attacks in Federated Learning via Critical Learning Periods Awareness
Gang Yan, Hao Wang, Xu Yuan, Jian Li
摘要
Federated learning (FL) is known to be susceptible to model poisoning attacks in which malicious clients hamper the accuracy of the global model by sending manipulated model updates to the central server during the FL training process. Existing defenses mainly focus on Byzantine-robust FL aggregations, and largely ignore the impact of the underlying deep neural network (DNN) that is used to FL training. Inspired by recent findings on critical learning periods (CLP) in DNNs, where small gradient errors have irrecoverable impact on the final model accuracy, we propose a new defense, called a CLP-aware defense against poisoning of FL (DeFL). The key idea of DeFL is to measure fine-grained differences between DNN model updates via an easy-to-compute federated gradient norm vector (FGNV) metric. Using FGNV, DeFL simultaneously detects malicious clients and identifies CLP, which in turn is leveraged to guide the adaptive removal of detected malicious clients from aggregation. As a result, DeFL not only mitigates model poisoning attacks on the global model but also is robust to detection errors. Our extensive experiments on three benchmark datasets demonstrate that DeFL produces significant performance gain over conventional defenses against state-of-the-art model poisoning attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- CriticalFL: A Critical Learning Periods Augmented Client Selection Framework for Efficient Federated LearningGang Yan, Hao Wang, Xu Yuan, Jian LiKDD 2023 · 被引用 36 次
- Byzantine-robust Decentralized Federated Learning via Dual-domain Clustering and Trust BootstrappingPeng Sun, Xinyang Liu, Zhibo Wang, Bo LiuCVPR 2024 · 被引用 21 次
- FedRoLA: Robust Federated Learning Against Model Poisoning via Layer-based AggregationGang Yan, Hao Wang, Xu Yuan, Jian LiKDD 2024 · 被引用 6 次
- Poisoning with a Pill: Circumventing Detection in Federated LearningHanxi Guo, Hao Wang, Tao Song, Tianhang Zheng 等AAAI 2026
它引用的顶会 Paper9
- Tackling the Objective Inconsistency Problem in Heterogeneous Federated OptimizationJianyu Wang, Qinghua Liu, Hao Liang, Gauri Joshi 等NeurIPS 2020 · 被引用 2,231 次
- Federated Learning with Matched AveragingHongyi Wang, Mikhail Yurochkin, Yuekai Sun, Dimitris S. Papailiopoulos 等ICLR 2020 · 被引用 1,368 次
- FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious ClientsZaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongKDD 2022 · 被引用 293 次
- The Early Phase of Neural Network TrainingJonathan Frankle, David J. Schwab, Ari S. MorcosICLR 2020 · 被引用 199 次
- Catastrophic Fisher Explosion: Early Phase Fisher Matrix Impacts GeneralizationStanislaw Jastrzebski, Devansh Arpit, Oliver Åstrand, Giancarlo Kerg 等ICML 2021 · 被引用 78 次
相关 Paper
- Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated LearningVirat Shejwalkar, Amir HoumansadrNDSS 2021
- FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client PerspectiveJingwei Sun, Ang Li, Louis DiValentin, Amin Hassanzadeh 等NeurIPS 2021 · 被引用 131 次
- Towards Attack-tolerant Federated Learning via Critical Parameter AnalysisSungwon Han, Sungwon Park, Fangzhao Wu, Sundong Kim 等ICCV 2023 · 被引用 23 次
- DeepSight: Mitigating Backdoor Attacks in Federated Learning Through Deep Model InspectionPhillip Rieger, Thien Duc Nguyen, Markus Miettinen, Ahmad-Reza SadeghiNDSS 2022
- Do We Really Need to Design New Byzantine-robust Aggregation Rules?Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun 等NDSS 2025
