Investigating the Label-flipping Attacks Impact in Federated Learning
At a glance
- الاستشهادات
- 1
- المراجع
- 21
- Comments
- 0
Abstract
Federated Learning (FL) is a collaborative model training approach that protects data privacy while allowing for model updates and optimization. However, FL is vulnerable to poisoning attacks due to its distributed nature. Among these attacks, label-flipping stands out for being straightforward to implement yet challenging to detect. Additionally, current research used to treat it as a black box, which could hinder the development of defense strategies. To fill this gap, this work investigates the impact of label-flipping attacks from multiple perspectives. Experiments are conducted using the MNIST and Fashion-MNIST dataset and an MLP (MultiLayer Perceptron) model. Results show that in label-flipping attacks, malicious clients primarily alter parameters in specific model components. Different flipping strategies also have varying effects on model parameters. Finally, this study compares label-flipping attacks with model poisoning attacks to better understand their differences. We’re looking forward to this work to offer insights for the FL community regarding label-flipping understanding and defense strategies.
Publication details
- DOI
- 10.1109/ispds62779.2024.10667549
- OpenAlex
- W4402474865
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
تسجيل الدخول للانضمام إلى النقاش.