Federated Learning: A Comparative Study of Defenses Against Poisoning Attacks

10Citations
Citations of this article
14Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Federated learning is a new paradigm where multiple data owners, referred to as clients, work together with a global server to train a shared machine learning model without disclosing their personal training data. Despite its many advantages, the system is vulnerable to client compromise by malicious agents attempting to modify the global model. Several defense algorithms against untargeted and targeted poisoning attacks on model updates in federated learning have been proposed and evaluated separately. This paper compares the performances of six state-of-the art defense algorithms—PCA + K-Means, KPCA + K-Means, CONTRA, KRUM, COOMED, and RPCA + PCA + K-Means. We explore a variety of situations not considered in the original papers. These include varying the percentage of Independent and Identically Distributed (IID) data, the number of clients, and the percentage of malicious clients. This comprehensive performance study provides the results that the users can use to select appropriate defense algorithms to employ based on the characteristics of their federated learning systems.

Cite

CITATION STYLE

APA

Carvalho, I., Huff, K., Gruenwald, L., & Bernardino, J. (2024). Federated Learning: A Comparative Study of Defenses Against Poisoning Attacks. Applied Sciences (Switzerland), 14(22). https://doi.org/10.3390/app142210706

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free