REVIEW 5 cited by
Learning to Detect Malicious Clients for Robust Federated Learning
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Federated learning systems are vulnerable to attacks from malicious clients. As the central server in the system cannot govern the behaviors of the clients, a rogue client may initiate an attack by sending malicious model updates to the server, so as to degrade the learning performance or enforce targeted model poisoning attacks (a.k.a. backdoor attacks). Therefore, timely detecting these malicious model updates and the underlying attackers becomes critically important. In this work, we propose a new framework for robust federated learning where the central server learns to detect and remove the malicious model updates using a powerful detection model, leading to targeted defense. We evaluate our solution in both image classification and sentiment analysis tasks with a variety of machine learning models. Experimental results show that our solution ensures robust federated learning that is resilient to both the Byzantine attacks and the targeted model poisoning attacks.
Forward citations
Cited by 5 Pith papers
-
Decoding FL Defenses: Systemization, Pitfalls, and Remedies
Many FL defenses are evaluated on overly easy datasets and attacks, and this paper demonstrates with case studies that those easy settings can make weak defenses look strong.
-
Byzantine-Resilient Zero-Order Optimization for Communication-Efficient Heterogeneous Federated Learning
CyBeR-0 performs Byzantine-robust federated learning by robustly aggregating zero-order gradient estimates in a low-dimensional random projection space, with non-convex convergence guarantees and large communication savings.
-
FLAegis: A Two-Layer Defense Framework for Federated Learning Against Poisoning Attacks
FLAegis defends federated learning by SAX-transforming client updates, spectral-clustering them to filter malicious clients, and applying FFT-based robust aggregation, outperforming several baselines on FEMNIST.
-
Measuring and Predicting Where and When Pathologists Focus their Visual Attention while Grading Whole Slide Images of Cancer
The submission combines an attention prediction abstract with a federated learning body, so the claimed result cannot be evaluated from the provided material.
-
Enabling Trustworthy Federated Learning via Remote Attestation for Mitigating Byzantine Threats
Sentinel signs a TEE-attested record of each client's control-flow and variable usage and admits only updates whose attestation passes, reaching ASR 0 for its modeled attacks.
Discussion (0). Continue with ORCID to comment.