Certifiably-Robust Federated Adversarial Learning via Randomized Smoothing
arXiv:2103.16031 · doi:10.1109/MASS52906.2021.00032
Abstract
Federated learning is an emerging data-private distributed learning framework, which, however, is vulnerable to adversarial attacks. Although several heuristic defenses are proposed to enhance the robustness of federated learning, they do not provide certifiable robustness guarantees. In this paper, we incorporate randomized smoothing techniques into federated adversarial training to enable data-private distributed learning with certifiable robustness to test-time adversarial perturbations. Our experiments show that such an advanced federated adversarial learning framework can deliver models as robust as those trained by the centralized training. Further, this enables provably-robust classifiers to -bounded adversarial perturbations in a distributed setup. We also show that one-point gradient estimation based training approach is faster than popular stochastic estimator based approach without any noticeable certified robustness differences.
9 pages, 12 figures
References in corpus (7)
- Explaining and Harnessing Adversarial Examples
- Federated Learning: Challenges, Methods, and Future Directions
- Federated Optimization: Distributed Machine Learning for On-Device Intelligence
- Certified Adversarial Robustness via Randomized Smoothing
- FedCluster: Boosting the Convergence of Federated Learning via Cluster-Cycling
- Federated Learning in Adversarial Settings
- FAT: Federated Adversarial Training