Master'sOpen Access

Designing intelligent Byzantines: Fall of robust aggregators in federated learning

2024
0 views
0 downloads
Advisor: Doç. Dr. Alptekin Küpçü

Abstract (EN)

In federated learning (FL), it is difficult to profile and verify each client, leading to a security threat, where by malicious clients, called Byzantines, may hamper the accuracy of the trained model by conveying poisoned models during training. Hence, the aggregation process at the parameter server should aim to minimize the detrimental effects of malicious clients. The Byzantine problem is typically analyzed from an outlier detection perspective, and is oblivious to the architecture of the neural network (NN) being trained. In this work, we first expose vulnerabilities of the robust aggregators, specifically the CC framework, and introduce novel attack strategies that can circumvent the defences of the state-of-the-art robust aggregators. Later, we argue that by extracting certain side information specific to the NN architecture, one can design even stronger attacks. Hence, inspired by sparse neural networks, we introduce a hybrid sparse Byzantine attack that is composed of two parts each targeting a different type of defence mechanism: one sparse part that attacks only certain NN parameters with higher sensitivity, and the other being more silent but accumulating over time. Then, we propose a new robust and fast defence mechanism that is effective against the proposed and other existing Byzantine attacks. Our code is publicly available here https://github.com/CRYPTO-KU/FL-Byzantine-Library

Author

Dr. Ahmet Kerem Özfatura

How to Cite

Ahmet Kerem Özfatura (Master Thesis). Designing intelligent Byzantines: Fall of robust aggregators in federated learning, 2024, Koç University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Koç University