Proposing a Novel Approach Based on GAN Neural Networks to Address Data Poisoning Attacks in Federated Learning
At a glance
- Citations
- 0
- References
- 18
- Comments
- 0
Abstract
Data poisoning attacks are one of the serious threats in federated learning, which can disrupt the performance of the central model by inj ecting poisoned data into local nodes. These attacks are particularly significant in cloud environments, where distributed and decentralized data are often managed, due to the increasing need for data security. Identifying and isolating poisoned data from clean data in local nodes is a fundamental step toward enhancing the security and stability of these systems. In this paper, a method based on Generative Adversarial Networks (GANs) is proposed, which can act as an effective tool for identifying poisoned samples. In the proposed method, the GAN discriminator's task shifts from solving a binary problem, as is standard in GANs, to identifying the true label of data in a multi-class problem. During the GAN training phase, the semantic information of the data, including the true labels, is incorporated into the discriminator. To evaluate the proposed method, experiments were conducted on the standard MNIST dataset. Compared to standard GANs, the proposed method showed better performance for classes where label-flipping data poisoning was applied. These results demonstrate the effectiveness and applicability of the proposed method in various federated learning environments. The presented method can be used as a solution to enhance the security of data and models in federated learning and to identify the true labels of data in cases where there is no prior information about the occurrence of an attack.
Publication details
- DOI
- 10.1109/csicc65765.2025.10967436
- OpenAlex
- W4409763718
- Document type
- conference-paper
- Language
- EN
- Last metadata update
Comments
Log in to join the discussion.