Security and Privacy Preserving Techniques for Federated Learning

dc.contributor.guideTripathy, Somanath
dc.coverage.spatial
dc.creator.researcherKasyap, Harsh
dc.date.accessioned2025-01-07T08:41:39Z
dc.date.available2025-01-07T08:41:39Z
dc.date.awarded2023
dc.date.completed2023
dc.date.registered2019
dc.description.abstractFederated learning (FL) has emerged as a promising approach for training machine learning newlinemodels on decentralized data without the need for data sharing. However, the nature newlineof FL introduces new security risks, particularly in the form of poisoning and inference newlineattacks. Poisoning attacks can manipulate the training data or local model to compromise newlinethe performance of the global model, while inference attacks extract sensitive information newlinefrom the model. Thus, there is a need to study and analyze the potential threats in FL newlineand design Byzantine-robust and inference-resistant FL. Byzantine-robust FL makes the newlinesystem resilient to attacks from a subset of malicious participants who may collude to undermine newlinethe training process. Meanwhile, inference-resistant FL aims to prevent attackers newlinefrom extracting information about the data used in training the model. newlineWe frame more insidious data and local model poisoning attacks targeting to degrade newlinethe global model performance in FL. These attacks are aggregation-agnostic and newlineadaptive in nature. We evaluate these attacks against state-of-the-art Byzantine-robust newlinedefenses, and observe that these novel adaptive poisoning attacks significantly degrade newlinethe performance by 5-10× than existing poisoning attacks. To defend against such adaptive newlinepoisoning attacks, we propose Byzantine-robust aggregation schemes. The proposed newlineschemes can detect and mitigate the impact of poisoned data or model on the model s newlineaccuracy and performance, by restricting the attack impact to 2-4%. newlineThis work also emphasizes the need for Byzantine-robust and inference-resistant FL newlineapproaches to ensure the robustness and privacy of the local models. Each of the existing newlineschemes addresses either poisoning or inference attacks. But, it can be observed newlinethat, inference-resistant FL is prone to poisoning attacks and vice versa. We propose a newlineByzantine-robust and inference-Resistant FL framework using a permissioned blockchain, newlinecalled PrivateFL. PrivateFL performs similarly to vanilla FL, while being resistant to newlinepoi
dc.description.note
dc.format.accompanyingmaterialDVD
dc.format.dimensions
dc.format.extentxxiii, 160p.
dc.identifier.urihttp://hdl.handle.net/10603/612461
dc.languageEnglish
dc.publisher.institutionDepartment of Computer Science and Engineering
dc.publisher.placePatna
dc.publisher.universityIndian Institute of Technology Patna
dc.relation
dc.rightsuniversity
dc.source.universityUniversity
dc.subject.keywordComputer Science
dc.subject.keywordComputer Science Software Engineering
dc.subject.keywordEngineering and Technology
dc.titleSecurity and Privacy Preserving Techniques for Federated Learning
dc.title.alternative
dc.type.degreePh.D.

Files

Original bundle

Now showing 1 - 5 of 13
Loading...
Thumbnail Image
Name:
01_title.pdf
Size:
45.88 KB
Format:
Adobe Portable Document Format
Description:
Attached File
Loading...
Thumbnail Image
Name:
02_prelim pages.pdf
Size:
132.83 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
03_content.pdf
Size:
31 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
04_abstarct.pdf
Size:
22.25 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
05_chapter 1.pdf
Size:
557.81 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.79 KB
Format:
Plain Text
Description: