用区块链+Krum机制,防住联邦学习中的恶意攻击。
Krum Federated Chain (KFC): Using blockchain to defend against adversarial attacks in Federated Learning
- 结合Krum算法与区块链共识,动态筛选可信模型更新。
- 即使所有参与方被攻破,仍可抵御任意配置的拜占庭和后门攻击。
- 适合高安全要求的分布式机器学习场景,如医疗、金融。
联邦学习通过在去中心化设备间协作训练模型,保护数据隐私,但其分布式特性使其易受恶意攻击。将区块链技术引入联邦学习,可提升系统安全性和完整性。本文首先测试了专为联邦环境设计的PoFL共识机制作为防御手段,在至少一名矿工未被攻破时,能有效抵御拜占庭和后门攻击。其次,提出Krum联邦链(KFC)新策略,融合Krum与PoFL,可在所有矿工均被攻破的情况下,依然防御任意配置的拜占庭或后门攻击。在图像分类数据集上的实验验证了该方法的有效性。
原文摘要 · Abstract (English)
Federated Learning presents a nascent approach to machine learning, enabling collaborative model training across decentralized devices while safeguarding data privacy. However, its distributed nature renders it susceptible to adversarial attacks. Integrating blockchain technology with Federated Learning offers a promising avenue to enhance security and integrity. In this paper, we tackle the potential of blockchain in defending Federated Learning against adversarial attacks. First, we test Proof of Federated Learning, a well known consensus mechanism designed ad-hoc to federated contexts, as a defense mechanism demonstrating its efficacy against Byzantine and backdoor attacks when at least one miner remains uncompromised. Second, we propose Krum Federated Chain, a novel defense strategy combining Krum and Proof of Federated Learning, valid to defend against any configuration of Byzantine or backdoor attacks, even when all miners are compromised. Our experiments conducted on image classification datasets validate the effectiveness of our proposed approaches.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。