A Survey on Federated Learning Poisoning Attacks and Defenses

Junchuan Lianga,Rong Wang,Chaosheng Feng,Chin-Chen Chang
2023-06-06
Abstract:As one kind of distributed machine learning technique, federated learning enables multiple clients to build a model across decentralized data collaboratively without explicitly aggregating the data. Due to its ability to break data silos, federated learning has received increasing attention in many fields, including finance, healthcare, and education. However, the invisibility of clients' training data and the local training process result in some security issues. Recently, many works have been proposed to research the security attacks and defenses in federated learning, but there has been no special survey on poisoning attacks on federated learning and the corresponding defenses. In this paper, we investigate the most advanced schemes of federated learning poisoning attacks and defenses and point out the future directions in these areas.
Cryptography and Security
What problem does this paper attempt to address?
The paper attempts to address the issue of poisoning attacks and their defense mechanisms in federated learning. Specifically, federated learning, as a distributed machine learning technique, allows multiple clients to collaboratively build a model without explicitly aggregating data. However, since the training data and local training processes of clients are not visible to other participants, this leads to some security issues, particularly poisoning attacks. These attacks can compromise model performance or exploit the federated learning framework for illegal activities. By investigating state-of-the-art federated learning poisoning attacks and defense schemes, the paper aims to fill the gap in the existing literature on this specific area and point out future research directions. The specific objectives include: 1. **Overview of types of federated learning poisoning attacks**: including data poisoning and model poisoning. 2. **Analysis of existing defense mechanisms**: including perturbation mechanisms, anomaly detection, etc. 3. **Identification of future research directions**: exploring how to further enhance the security and robustness of federated learning. Through these efforts, the paper hopes to provide a comprehensive reference for researchers and practitioners to address the issue of poisoning attacks in federated learning.