Free-riders in Federated Learning: Attacks and Defenses
arXiv:1911.12560
Abstract
Federated learning is a recently proposed paradigm that enables multiple clients to collaboratively train a joint model. It allows clients to train models locally, and leverages the parameter server to generate a global model by aggregating the locally submitted gradient updates at each round. Although the incentive model for federated learning has not been fully developed, it is supposed that participants are able to get rewards or the privilege to use the final global model, as a compensation for taking efforts to train the model. Therefore, a client who does not have any local data has the incentive to construct local gradient updates in order to deceive for rewards. In this paper, we are the first to propose the notion of free rider attacks, to explore possible ways that an attacker may construct gradient updates, without any local training data. Furthermore, we explore possible defenses that could detect the proposed attacks, and propose a new high dimensional detection method called STD-DAGMM, which particularly works well for anomaly detection of model parameters. We extend the attacks and defenses to consider more free riders as well as differential privacy, which sheds light on and calls for future research in this field.
References in corpus (2)
Cited by in corpus (12)
- An Experimental Study of Byzantine-Robust Aggregation Schemes in Federated Learning
- Secure and Trustworthy Artificial Intelligence-Extended Reality (AI-XR) for Metaverses
- A Survey on Vulnerability of Federated Learning: A Learning Algorithm Perspective
- PASS: A Parameter Audit-based Secure and Fair Federated Learning Scheme against Free-Rider Attack
- Free-Rider Games for Federated Learning with Selfish Clients in NextG Wireless Networks
- Robust Asymmetric Heterogeneous Federated Learning with Corrupted Clients
- Auction Based Clustered Federated Learning in Mobile Edge Computing System
- An Exploratory Analysis on Users' Contributions in Federated Learning
- One for One, or All for All: Equilibria and Optimality of Collaboration in Federated Learning
- Security and Privacy Issues and Solutions in Federated Learning for Digital Healthcare
- Data-Free Evaluation of User Contributions in Federated Learning
- Marketplace for AI Models