Survey on Federated Learning Threats: concepts, taxonomy on attacks and defences, experimental study and challenges
arXiv:2201.08135 · doi:10.1016/j.inffus.2022.09.011
Abstract
Federated learning is a machine learning paradigm that emerges as a solution to the privacy-preservation demands in artificial intelligence. As machine learning, federated learning is threatened by adversarial attacks against the integrity of the learning model and the privacy of data via a distributed approach to tackle local and global learning. This weak point is exacerbated by the inaccessibility of data in federated learning, which makes harder the protection against adversarial attacks and evidences the need to furtherance the research on defence methods to make federated learning a real solution for safeguarding data privacy. In this paper, we present an extensive review of the threats of federated learning, as well as as their corresponding countermeasures, attacks versus defences. This survey provides a taxonomy of adversarial attacks and a taxonomy of defence methods that depict a general picture of this vulnerability of federated learning and how to overcome it. Likewise, we expound guidelines for selecting the most adequate defence method according to the category of the adversarial attack. Besides, we carry out an extensive experimental study from which we draw further conclusions about the behaviour of attacks and defences and the guidelines for selecting the most adequate defence method according to the category of the adversarial attack. This study is finished leading to meditated learned lessons and challenges.
References in corpus (24)
- Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- Federated Machine Learning: Concept and Applications
- Privacy-preserving Federated Learning based on Multi-key Homomorphic Encryption
- iDLG: Improved Deep Leakage from Gradients
- Can You Really Backdoor Federated Learning?
- Feature Inference Attack on Model Predictions in Vertical Federated Learning
- Federated Learning for Healthcare Domain - Pipeline, Applications and Challenges
- Learning to Detect Malicious Clients for Robust Federated Learning
- Wikidata as a seed for Web Extraction
- Federated Learning and Differential Privacy: Software tools analysis, the Sherpa.ai FL framework and methodological guidelines for preserving data privacy
- GRNN: Generative Regression Neural Network -- A Data Leakage Attack for Federated Learning
- FastSecAgg: Scalable Secure Aggregation for Privacy-Preserving Federated Learning
- Label Leakage and Protection in Two-party Split Learning
- Mitigating Backdoor Attacks in Federated Learning
- Privacy and Robustness in Federated Learning: Attacks and Defenses
- Backdoor attacks and defenses in feature-partitioned collaborative learning
- Eavesdrop the Composition Proportion of Training Labels in Federated Learning
- Hybrid Differentially Private Federated Learning on Vertically Partitioned Data
- On the relationship between (secure) multi-party computation and (secure) federated learning
- FedXGBoost: Privacy-Preserving XGBoost for Federated Learning
- Voting-based Approaches For Differentially Private Federated Learning
- SAFE: Secure Aggregation with Failover and Encryption
- Holdout SGD: Byzantine Tolerant Federated Learning
Cited by in corpus (13)
- Decentralized Federated Learning: Fundamentals, State of the Art, Frameworks, Trends, and Challenges
- Explainable Artificial Intelligence (XAI) 2.0: A Manifesto of Open Challenges and Interdisciplinary Research Directions
- Federated Learning Survey: A Multi-Level Taxonomy of Aggregation Techniques, Experimental Insights, and Future Frontiers
- Threats and Defenses in Federated Learning Life Cycle: A Comprehensive Survey and Challenges
- Studying the Robustness of Anti-adversarial Federated Learning Models Detecting Cyberattacks in IoT Spectrum Sensors
- A Design Framework for operationalizing Trustworthy Artificial Intelligence in Healthcare: Requirements, Tradeoffs and Challenges for its Clinical Adoption
- Federated brain tumor segmentation: an extensive benchmark
- Privacy-Preserving Federated Learning with Differentially Private Hyperdimensional Computing
- Defending Against Diverse Attacks in Federated Learning Through Consensus-Based Bi-Level Optimization
- From Privacy to Trust in the Agentic Era: A Taxonomy of Challenges in Trustworthy Federated Learning Through the Lens of Trust Report 2.0
- Attacks on Robust Distributed Learning Schemes via Sensitivity Curve Maximization
- An Empirical Analysis of Federated Learning Models Subject to Label-Flipping Adversarial Attack
- RAB-DEF: Dynamic and explainable defense against adversarial attacks in Federated Learning to fair poor clients