Security and Privacy Preserving Techniques for Federated Learning
| dc.contributor.guide | Tripathy, Somanath | |
| dc.coverage.spatial | ||
| dc.creator.researcher | Kasyap, Harsh | |
| dc.date.accessioned | 2025-01-07T08:41:39Z | |
| dc.date.available | 2025-01-07T08:41:39Z | |
| dc.date.awarded | 2023 | |
| dc.date.completed | 2023 | |
| dc.date.registered | 2019 | |
| dc.description.abstract | Federated learning (FL) has emerged as a promising approach for training machine learning newlinemodels on decentralized data without the need for data sharing. However, the nature newlineof FL introduces new security risks, particularly in the form of poisoning and inference newlineattacks. Poisoning attacks can manipulate the training data or local model to compromise newlinethe performance of the global model, while inference attacks extract sensitive information newlinefrom the model. Thus, there is a need to study and analyze the potential threats in FL newlineand design Byzantine-robust and inference-resistant FL. Byzantine-robust FL makes the newlinesystem resilient to attacks from a subset of malicious participants who may collude to undermine newlinethe training process. Meanwhile, inference-resistant FL aims to prevent attackers newlinefrom extracting information about the data used in training the model. newlineWe frame more insidious data and local model poisoning attacks targeting to degrade newlinethe global model performance in FL. These attacks are aggregation-agnostic and newlineadaptive in nature. We evaluate these attacks against state-of-the-art Byzantine-robust newlinedefenses, and observe that these novel adaptive poisoning attacks significantly degrade newlinethe performance by 5-10× than existing poisoning attacks. To defend against such adaptive newlinepoisoning attacks, we propose Byzantine-robust aggregation schemes. The proposed newlineschemes can detect and mitigate the impact of poisoned data or model on the model s newlineaccuracy and performance, by restricting the attack impact to 2-4%. newlineThis work also emphasizes the need for Byzantine-robust and inference-resistant FL newlineapproaches to ensure the robustness and privacy of the local models. Each of the existing newlineschemes addresses either poisoning or inference attacks. But, it can be observed newlinethat, inference-resistant FL is prone to poisoning attacks and vice versa. We propose a newlineByzantine-robust and inference-Resistant FL framework using a permissioned blockchain, newlinecalled PrivateFL. PrivateFL performs similarly to vanilla FL, while being resistant to newlinepoi | |
| dc.description.note | ||
| dc.format.accompanyingmaterial | DVD | |
| dc.format.dimensions | ||
| dc.format.extent | xxiii, 160p. | |
| dc.identifier.uri | http://hdl.handle.net/10603/612461 | |
| dc.language | English | |
| dc.publisher.institution | Department of Computer Science and Engineering | |
| dc.publisher.place | Patna | |
| dc.publisher.university | Indian Institute of Technology Patna | |
| dc.relation | ||
| dc.rights | university | |
| dc.source.university | University | |
| dc.subject.keyword | Computer Science | |
| dc.subject.keyword | Computer Science Software Engineering | |
| dc.subject.keyword | Engineering and Technology | |
| dc.title | Security and Privacy Preserving Techniques for Federated Learning | |
| dc.title.alternative | ||
| dc.type.degree | Ph.D. |
Files
Original bundle
1 - 5 of 13
Loading...
- Name:
- 01_title.pdf
- Size:
- 45.88 KB
- Format:
- Adobe Portable Document Format
- Description:
- Attached File
Loading...
- Name:
- 02_prelim pages.pdf
- Size:
- 132.83 KB
- Format:
- Adobe Portable Document Format
License bundle
1 - 1 of 1