Skip to main content
QUICK REVIEW

[논문 리뷰] SignGuard: Byzantine-robust Federated Learning through Collaborative Malicious Gradient Filtering.

Jian Xu, Shao‐Lun Huang|arXiv (Cornell University)|2021. 09. 13.
Privacy-Preserving Technologies in Data참고 문헌 39인용 수 11
한 줄 요약

SignGuard는 기울기 부호, 크기 및 유사도 통계의 협업 분석을 통해 악성 기울기를 탐지하고 필터링하는 비잔틴 내성 강화된 피어드 학습 프레임워크를 제안한다. 비아이디어 데이터 환경에서 이미지 및 텍스트 분류 작업에서 기존 통계 기반 방어 대비 고도화된 모델 오염 공격에 대해 뛰어난 성능을 발휘한다.

ABSTRACT

Gradient-based training in federated learning is known to be vulnerable to faulty/malicious worker nodes, which are often modeled as Byzantine clients. Previous work either makes use of auxiliary data at parameter server to verify the received gradients or leverages statistic-based methods to identify and remove malicious gradients from Byzantine clients. In this paper, we acknowledge that auxiliary data may not always be available in practice and focus on the statistic-based approach. However, recent work on model poisoning attacks have shown that well-crafted attacks can circumvent most of existing median- and distance-based statistical defense methods, making malicious gradients indistinguishable from honest ones. To tackle this challenge, we show that the element-wise sign of gradient vector can provide valuable insight in detecting model poisoning attacks. Based on our theoretical analysis of state-of-the-art attack, we propose a novel approach, extit{SignGuard}, to enable Byzantine-robust federated learning through collaborative malicious gradient filtering. More precisely, the received gradients are first processed to generate relevant magnitude, sign, and similarity statistics, which are then collaboratively utilized by multiple, parallel filters to eliminate malicious gradients before final aggregation. We further provide theoretical analysis of SignGuard by quantifying its convergence with appropriate choice of learning rate and under non-IID training data. Finally, extensive experiments of image and text classification tasks - including MNIST, Fashion-MNIST, CIFAR-10, and AG-News - are conducted together with recently proposed attacks and defense strategies. The numerical results demonstrate the effectiveness and superiority of our proposed approach.

연구 동기 및 목표

  • 학습 중 악성 기울기를 주입하는 비잔틴 클라이언트에 의한 피어드 학습의 취약성을 해결한다.
  • 고도화된 모델 오염 공격에 의해 우회될 수 있는 기존 통계 기반 방어의 한계를 극복한다.
  • 보조 데이터에 의존하지 않는 방어 메커니즘을 개발하여 실세계 구현에 실용성을 확보한다.
  • 내재된 기울기 특성의 활용을 통해 비아이디어 데이터 분포에서도 안정적인 수렴을 가능하게 한다.
  • 적절한 학습률 설정 하에서 제안된 방법에 대한 이론적 수렴 보장을 제공한다.

제안 방법

  • 도착한 기울기에서 크기, 원소별 부호, 클라이언트 간 쌍별 유사도의 세 가지 핵심 통계를 추출한다.
  • 이 통계들을 협업적으로 분석하여 악성 기울기를 탐지하고 격리하는 다중 병렬 필터를 구현한다.
  • 최신 오염 공격 이론 분석에 기반해 기울기의 부호 패턴을 구분 특징으로 활용한다.
  • 최종 모델 집합 이전에 부호와 크기 통계의 병합 기반으로 이상치를 제거하는 필터링 메커니즘을 적용한다.
  • 적응형 학습률 제어를 통한 표준 피어드 평균화 과정에 필터링된 기울기를 통합한다.
  • 이론적 분석을 통해 적절한 학습률 선택 하에서 비아이디어 데이터에서의 수렴을 입증한다.

실험 결과

연구 질문

  • RQ1기울기 벡터의 원소별 부호가 피어드 학습에서 모델 오염 공격을 탐지하는 신뢰할 수 있는 신호가 될 수 있는가?
  • RQ2부호, 크기 및 유사도 통계를 기반으로 한 협업 필터링은 고도화된 비잔틴 공격에 대해 얼마나 효과적인가?
  • RQ3기존 통계 기반 방어 대비 SignGuard는 비아이디어 데이터 분포에서 수렴성과 모델 정확도를 유지하는가?
  • RQ4보조 데이터나 모델 가정 없이 SignGuard는 악성 기울기를 탐지하고 필터링할 수 있는가?
  • RQ5이미지 및 텍스트 분류 작업에서 최근에 제안된 공격 및 방어 대비 SignGuard의 내성성과 성능은 어떠한가?

주요 결과

  • SignGuard는 중앙값 및 거리 기반 방어를 우회하도록 설계된 공격에도 악성 기울기를 효과적으로 탐지하고 필터링한다.
  • 다양한 오염 공격 시나리오 하에서 MNIST, Fashion-MNIST, CIFAR-10 및 AG-News에서 베이스라인 방어 대비 높은 테스트 정확도를 달성한다.
  • 부호, 크기 및 유사도 통계를 통합한 협업 필터링은 단일 통계 기반 접근 대비 뚜렷한 내성성 향상을 이룬다.
  • 이론적 분석을 통해 적절한 학습률 선택 하에서 비아이디어 데이터에서 SignGuard의 수렴이 확인된다.
  • 실험 결과 SignGuard는 최대 30%의 클라이언트가 비잔틴일 경우에도 높은 모델 성능을 유지한다.
  • 다양한 피어드 학습 벤치마크에서 내성성과 일반화 능력 측면에서 최신 기술 대비 뛰어난 성능을 발휘한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.