LoMar: A compression-based local defence against poisoning attacks on federated learning
Abstract
A decentralized machine learning system called Federated Learning (FL) distributes training data across network clients for efficiency. A new research suggests that FL's mobile edge computing architecture, which uses IoT devices to protect user privacy, may be vulnerable to poisoning attacks by distant clients. FL poisoning attacks may be prevented using the Local Malicious Factor (LoMar) prevention mechanism. Initially, LoMar evaluated all remote client model changes. Their relative distribution across their neighbors is determined via kernel density estimation. In Phase II, statistical methods estimate the ideal threshold for separating bad and clean updates. Our defensive technique protects the FL system after thorough evaluation on four real-world datasets. Most notably, label-flipping is used to evaluate the defense's effectiveness on Amazon. LoMar outperforms FG+Krum in average testing accuracy (90.1% to 97.0%) in target label testing (96.0% to 98.8%).
How this paper connects to the literature. Drag to explore, click any node to open that paper.
